Skip to finding
important · Research

Unauthenticated SAP CAP requests can expose multitenancy credentials and alter tenant data.

Affects

SAP Cloud Application Programming Model multitenant applications using the @sap/cds-mtxs Node.js library in cloud deployments.

The path applies to multitenant applications using @sap/cds-mtxs with extensibility enabled, and the disclosed credentials can be used to replace or delete tenant data.

Detail and 1 source

SAP's September material identifies affected release lines and a remediation note.

Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Tuesday, September 8, 2026