Authentication Bypass in SAP Commerce Cloud by SAP
CVE-2026-58231
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 11 August 2026
Badges
What is CVE-2026-58231?
CVE-2026-58231 is a serious vulnerability affecting SAP Commerce Cloud, a platform that facilitates e-commerce solutions for businesses by enabling the creation and management of online commerce sites. This vulnerability allows unauthenticated attackers to exploit a default authentication client by inputting specially crafted data into specific functions that do not have adequate validation. The exploitation of this weakness can lead to arbitrary code execution, enabling attackers to compromise internal components within the SAP Commerce Cloud environment. As a result, organizations using this platform may face severe threats to the confidentiality, integrity, and availability of their systems and data.
Potential Impact of CVE-2026-58231
-
Arbitrary Code Execution: The vulnerability allows attackers to execute arbitrary code on affected systems, which can lead to unauthorized control and operation of the compromised SAP Commerce Cloud instances.
-
Compromise of Confidentiality and Integrity: Successful exploitation could enable attackers to access sensitive information stored within the platform, leading to data breaches and potential manipulation of critical data, thereby undermining trust and operational effectiveness.
-
Disruption of Services: With the possibility of compromising internal components, organizations may face significant downtime and service disruption, affecting their ability to conduct e-commerce operations and maintain customer trust.
Affected Version(s)
SAP Commerce Cloud (Data Hub Adapter) COM_CLOUD 2211
SAP Commerce Cloud (Data Hub Adapter) 2211-JDK21
News Articles
Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure
Hackers started exploiting a critical vulnerability in SAP Commerce Cloud just three days after its public disclosure.
4 weeks ago
SAP Commerce Cloud Vulnerability Targeted After Patch - IT Security News
2026-08-16 18:08 A maximum-severity vulnerability in SAP Commerce Cloud is reportedly facing exploitation attempts only days after SAP released a security update. Tracked as CVE-2026-58231,...
4 weeks ago
SAP Commerce Cloud CVE-2026-58231 Exploited in the Wild - IT Security News
Vendors can use your data to provide services. Declining a vendor can stop them from using the data you shared.Exponential Interactive, Inc d/b/a VDX.tvCookie duration: 90 (days).Data collected and processed:...
1 month ago
References
CVSS V3.1
Timeline
- 📈
Vulnerability started trending
- 👾
Exploit known to exist
- 📰
First article discovered by The Hacker News
Vulnerability published
Vulnerability Reserved