Authentication Bypass in SAP Commerce Cloud by SAP
CVE-2026-58231
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 11 August 2026
Badges
What is CVE-2026-58231?
CVE-2026-58231 is a serious vulnerability affecting SAP Commerce Cloud, a platform that facilitates e-commerce solutions for businesses by enabling the creation and management of online commerce sites. This vulnerability allows unauthenticated attackers to exploit a default authentication client by inputting specially crafted data into specific functions that do not have adequate validation. The exploitation of this weakness can lead to arbitrary code execution, enabling attackers to compromise internal components within the SAP Commerce Cloud environment. As a result, organizations using this platform may face severe threats to the confidentiality, integrity, and availability of their systems and data.
Potential Impact of CVE-2026-58231
-
Arbitrary Code Execution: The vulnerability allows attackers to execute arbitrary code on affected systems, which can lead to unauthorized control and operation of the compromised SAP Commerce Cloud instances.
-
Compromise of Confidentiality and Integrity: Successful exploitation could enable attackers to access sensitive information stored within the platform, leading to data breaches and potential manipulation of critical data, thereby undermining trust and operational effectiveness.
-
Disruption of Services: With the possibility of compromising internal components, organizations may face significant downtime and service disruption, affecting their ability to conduct e-commerce operations and maintain customer trust.
Affected Version(s)
SAP Commerce Cloud (Data Hub Adapter) COM_CLOUD 2211
SAP Commerce Cloud (Data Hub Adapter) 2211-JDK21
News Articles
SAP Commerce Cloud RCE Flaw Actively Exploited | eSecurity Planet
SAP Commerce Cloud flaw CVE-2026-58231 is being actively exploited in the wild.
23 hours ago
Max severity SAP Commerce Cloud flaw now targeted in attacks
A maximum-severity SAP Commerce Cloud remote code execution vulnerability patched three days ago is already being targeted in attacks, according to threat intelligence company Defused.
1 day ago
SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code
SAP fixes CVE-2026-58231, a CVSS 10.0 Commerce Cloud flaw that could let unauthenticated attackers execute arbitrary code.
3 days ago
References
CVSS V3.1
Timeline
- 📈
Vulnerability started trending
- 👾
Exploit known to exist
- 📰
First article discovered by The Hacker News
Vulnerability published
Vulnerability Reserved