SAP Knowledge Base Article - Preview

3747165 - Not Applicable for SAP Commerce Cloud 2205 SmartEdit-Related Extensions — CVE-2026-32635 (Angular i18n Attribute-Path XSS)

Symptom

Vulnerability Information

  • CVE: CVE-2026-32635
  • Black Duck: BDSA-2026-4056
  • Vulnerability type: specific Angular i18n attribute binding paths may bypass sanitization and lead to XSS
  • NVD baseline rating: CVSS 4.0 8.6 (High) (generic component-level context)


Read more...

Environment

  • SAP Commerce Cloud 2205 (2211 is unaffected because it adopts the latest Angular version)
  • Frontend module scope:
    • smartedit
    • personalizationsmartedit
    • personalizationsearchsmartedit
    • merchandisingsmartedit
  • Affected component baseline in scope: Angular 8.2.14

Product

SAP Commerce 2205 ; SAP Commerce Cloud all versions

Keywords

SmartEdit, Angular, CVE-2026-32635 , KBA , CEC-SCC-COM-SEDIT , SmartEdit , Problem

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.