Symptom
Background
BlackDuck security scans have flagged five CVEs against Angular packages bundled with SAP Commerce Cloud SmartEdit. All five vulnerabilities were fixed upstream in Angular 20.3.25, 21.2.17, and 22.0.1.
This KBA documents why none of these CVEs are exploitable in the OOTB SmartEdit installation, explains the architectural reasons for each finding, and provides guidance for customers who have built custom SmartEdit extensions.
The modules analysed in this audit are:
- smartedit / smartedit-container
- cmssmartedit / cmssmarteditcontainer
- ysmarteditmodule
- personalizationsmartedit / personalizationsmarteditcontainer
- personalizationpromotionssmartedit
- personalizationsearchsmartedit
- merchandisingsmartedit
CVE Summary Table
|
CVE |
Package |
Type |
OOTB Verdict |
Rescored CVSS 4.0 |
|
CVE-2026-54268 |
@angular/common |
DoS (DatePipe / formatDate) |
Not Applicable |
0.0 |
|
CVE-2026-54267 |
@angular/core |
DOM Clobbering / Cache Poisoning (SSR Hydration) |
Not Applicable |
0.0 |
|
CVE-2026-54266 |
@angular/common |
Cache Key Hash Collision (HttpTransferCache / SSR) |
Not Applicable |
0.0 |
|
CVE-2026-54265 |
@angular/compiler |
Sanitizer Bypass (Two-Way Binding on DOM Properties) |
Not Applicable |
0.0 |
|
CVE-2026-54264 |
@angular/service-worker |
Sensitive Header Leakage (Cross-Origin Redirect) |
Not Applicable |
0.0 |
Read more...
Environment
SAP Commerce Cloud
Product
Keywords
CVE-2026-54268, CVE-2026-54267, CVE-2026-54266, CVE-2026-54265, CVE-2026-54264 , KBA , CEC-SCC-COM-SEDIT , SmartEdit , Problem
About this page
This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).Search for additional results
Visit SAP Support Portal's SAP Notes and KBA Search.
SAP Knowledge Base Article - Preview