SAP Knowledge Base Article - Preview

3776718 - Angular v19.2.25 CVE Vulnerabilities Not Applicable to SAP Commerce Cloud SmartEdit

Symptom

Background

BlackDuck security scans have flagged five CVEs against Angular packages bundled with SAP Commerce Cloud SmartEdit. All five vulnerabilities were fixed upstream in Angular 20.3.25, 21.2.17, and 22.0.1.

This KBA documents why none of these CVEs are exploitable in the OOTB SmartEdit installation, explains the architectural reasons for each finding, and provides guidance for customers who have built custom SmartEdit extensions.

The modules analysed in this audit are:

  • smartedit / smartedit-container
  • cmssmartedit / cmssmarteditcontainer
  • ysmarteditmodule
  • personalizationsmartedit / personalizationsmarteditcontainer
  • personalizationpromotionssmartedit
  • personalizationsearchsmartedit
  • merchandisingsmartedit

CVE Summary Table

CVE

Package

Type

OOTB Verdict

Rescored CVSS 4.0

CVE-2026-54268

@angular/common

DoS (DatePipe / formatDate)

Not Applicable

0.0

CVE-2026-54267

@angular/core

DOM Clobbering / Cache Poisoning (SSR Hydration)

Not Applicable

0.0

CVE-2026-54266

@angular/common

Cache Key Hash Collision (HttpTransferCache / SSR)

Not Applicable

0.0

CVE-2026-54265

@angular/compiler

Sanitizer Bypass (Two-Way Binding on DOM Properties)

Not Applicable

0.0

CVE-2026-54264

@angular/service-worker

Sensitive Header Leakage (Cross-Origin Redirect)

Not Applicable

0.0


Read more...

Environment

SAP Commerce Cloud

Product

SAP Commerce Cloud all versions

Keywords

CVE-2026-54268, CVE-2026-54267, CVE-2026-54266, CVE-2026-54265, CVE-2026-54264 , KBA , CEC-SCC-COM-SEDIT , SmartEdit , Problem

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.