Authentication Bypass in SAP Commerce Cloud by SAP
CVE-2026-58231

10CRITICAL

Key Information:

Vendor

SAP

Vendor
CVE Published:
11 August 2026

Badges

📈 Trended📈 Score: 5,630👾 Exploit Exists📰 News Worthy

What is CVE-2026-58231?

CVE-2026-58231 is a serious vulnerability affecting SAP Commerce Cloud, a platform that facilitates e-commerce solutions for businesses by enabling the creation and management of online commerce sites. This vulnerability allows unauthenticated attackers to exploit a default authentication client by inputting specially crafted data into specific functions that do not have adequate validation. The exploitation of this weakness can lead to arbitrary code execution, enabling attackers to compromise internal components within the SAP Commerce Cloud environment. As a result, organizations using this platform may face severe threats to the confidentiality, integrity, and availability of their systems and data.

Potential Impact of CVE-2026-58231

  1. Arbitrary Code Execution: The vulnerability allows attackers to execute arbitrary code on affected systems, which can lead to unauthorized control and operation of the compromised SAP Commerce Cloud instances.

  2. Compromise of Confidentiality and Integrity: Successful exploitation could enable attackers to access sensitive information stored within the platform, leading to data breaches and potential manipulation of critical data, thereby undermining trust and operational effectiveness.

  3. Disruption of Services: With the possibility of compromising internal components, organizations may face significant downtime and service disruption, affecting their ability to conduct e-commerce operations and maintain customer trust.

Affected Version(s)

SAP Commerce Cloud (Data Hub Adapter) COM_CLOUD 2211

SAP Commerce Cloud (Data Hub Adapter) 2211-JDK21

News Articles

Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure

Hackers started exploiting a critical vulnerability in SAP Commerce Cloud just three days after its public disclosure.

4 weeks ago

SAP Commerce Cloud Vulnerability Targeted After Patch - IT Security News

2026-08-16 18:08 A maximum-severity vulnerability in SAP Commerce Cloud is reportedly facing exploitation attempts only days after SAP released a security update. Tracked as CVE-2026-58231,...

4 weeks ago

SAP Commerce Cloud CVE-2026-58231 Exploited in the Wild - IT Security News

Vendors can use your data to provide services. Declining a vendor can stop them from using the data you shared.Exponential Interactive, Inc d/b/a VDX.tvCookie duration: 90 (days).Data collected and processed:...

1 month ago

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • 📈

    Vulnerability started trending

  • 👾

    Exploit known to exist

  • 📰

    First article discovered by The Hacker News

  • Vulnerability published

  • Vulnerability Reserved

.