CVE-2026-58231

Published Aug 11, 2026

Last updated 2 days ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-58231 is a recently disclosed vulnerability impacting SAP Commerce Cloud, specifically affecting versions 2211 and 2211-JDK21. This flaw, categorized as an improper authorization issue, allows an unauthenticated attacker to exploit a default authentication client. By submitting specially crafted input to certain functions that lack adequate validation, the attacker can achieve successful exploitation. The vulnerability enables arbitrary code execution and the compromise of internal components within the SAP Commerce Cloud environment. This can lead to a significant impact on the confidentiality, integrity, and availability of the application.

Description
SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation. Successful exploitation could enable arbitrary code execution and compromise internal components, resulting in high impact on confidentiality, integrity, and availability of the application.
Source
cna@sap.com
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Secondary
Base score
10
Impact score
6
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

cna@sap.com
CWE-94

Social media

Hype score
Not currently trending
  1. Warning: multiple critical code injection, out-of-bounds write in #SAP #commercecloud #netweaver #MII CVE-2026-58231, CVE-2026-44772, CVE-2026-34265 & CVE-2026-44758 CVSS: 10-9.1 The first one is actively exploited #Patch #Patch #Patch

    @CCBalert

    18 Aug 2026

    238 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. 🚨 CVE-2026-58231: Critical SAP Commerce Cloud RCE CVSS 10.0 • Pre-auth • Remote code execution • Public PoC/research available • Exploitation activity reported https://t.co/6Y84gw4sys #CVE #SAP #CyberSecurity

    @stem__shop

    18 Aug 2026

    7 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. China-nexus APT is exploiting VMware vCenter CVE-2026-59310 to drop Babuk-derived ransomware, while SAP Commerce Cloud CVE-2026-58231 fell to attackers three days after disclosure. #CyberSecurity #BlueTeam #Ransomware https://t.co/iQq0QuH5Uz

    @itsalreadywhen

    17 Aug 2026

    9 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  4. 🚨 CVE-of-the-Day: CVE-2026-58231 — SAP Commerce Cloud, unauthenticated RCE CVSS: 10.0 | EPSS: N/A (too new to be scored) The Data Hub Adapter ships with a default auth client that skips authorization checks, letting an attacker send crafted input and execute code. No login

    @YourDailyCVE

    17 Aug 2026

    6 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  5. SAP Commerce Cloud CVE-2026-58231 Targeted in Exploitation Attempts Days After Patch: A maximum-severity security vulnerability impacting SAP Commerce Cloud is witnessing active exploitation efforts. The vulnerability, tracked as CVE-2026-58231, is rated… https://t.co/cHomgHasH

    @shah_sheikh

    17 Aug 2026

    35 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. 🔒 #CyberSecurity CVE-2026-58231: Critical SAP Commerce Cloud RCE Exploited 3 Days After Disclosu… "SecurityWeek reported that CVE-2026-58231, a critical vulnerability in SAP Commerce Cloud,…" 🔗 https://t.co/J1S6dloBJV #CyberSecurity #ThreatIntel #cve #zeroday

    @SecurityAr58409

    17 Aug 2026

    37 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. For defenders, sap commerce cloud cve-2026-58231 is a reminder that patch wind… should move fast. SAP Commerce Cloud CVE-2026-58231 is a CVSS 10.0 flaw with reported exploitation attempts w… 🔗 Details → https://t.co/OPIxTTRMff

    @SocXAInvaders

    17 Aug 2026

    15 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. Legacy exposure keeps paying off for attackers. SAP Commerce Cloud CVE-2026-58231 Is a Reminder That Patc… SAP Commerce Cloud CVE-2026-58231 is a CVSS 10.0 flaw with reported exploitation attempts w… 🔗 Read → https://t.co/z7LOzNy7iE

    @fynn_JourX

    17 Aug 2026

    25 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. 🛑 SAP Commerce Cloud CVE-2026-58231 Is a Reminder That Patch Windows Are… SAP Commerce Cloud CVE-2026-58231 is a CVSS 10.0 flaw with reported exploitation attempts w… 🔗 Details → https://t.co/mMWSPMELab

    @lucasverdan

    17 Aug 2026

    47 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  10. ⚠️SAP Commerce Cloudの脆弱性、修正から3日後に悪用試行始まる:CVE-2026-58231 🪙macOS画面共有機能の脆弱性を攻撃者が悪用し、モネロマイナーを展開:CVE-2026-65400 🚨GeoServerにおけるパッチ未提供のゼロデイをハ

    @MachinaRecord

    17 Aug 2026

    106 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. استغلال CVE-2026-58231 في SAP Commerce Cloud داخل بيئات حقيقية يعني أن التعامل معها يجب أن ينتقل من المتابعة إلى التحقق العاجل. تكمن الأهمية في أن منصات التجارة الرقمية

    @fad_777

    16 Aug 2026

    78 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. ⚠️ ثغرة بخطورة قصوى في منصة تجارة إلكترونية تُستغل فعلياً دون شفرة استغلال معلنة. المعرّف : CVE-2026-58231 درجة الخطورة : 10.0 (CVSS) - Critical الإصدارات المتأثرة : Commerc

    @KasperskyDev

    16 Aug 2026

    175 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  13. Attackers are actively exploiting CVE-2026-58231 in SAP Commerce Cloud days after the patch, enabling unauthenticated arbitrary code execution and likely targeting high-impact confidentiality, integrity, and availability losses. https://t.co/qwxE0JhfxS

    @Cyber_O51NT

    16 Aug 2026

    439 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  14. Attackers are targeting SAP Commerce Cloud CVE-2026-58231, a CVSS 10.0 flaw enabling unauthenticated code execution. Exploitation began days after patching. Defenders should act now. 👇 #Aiz_Cyber #CVE #CloudSecurity https://t.co/BfRydbdcfS

    @Aiz_Cyber

    16 Aug 2026

    38 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  15. SAP Commerce Cloud CVE-2026-58231 Exploited in the Wild: Attackers are actively exploiting a maximum severity SAP Commerce Cloud vulnerability, tracked as CVE-2026-58231, just days after SAP released a patch. A critical SAP Commerce Cloud vulnerability,… https://t.co/pdKOCXq0iW

    @shah_sheikh

    15 Aug 2026

    49 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  16. CyberSec Daily ✓ · 🔴 Red Team · August 15, 2026 🎯 SAP’s CVSS 10 flaw shows why external attack-surface validation matters CVE-2026-58231 affects SAP Commerce Cloud Data Hub Adapter versions COM_CLOUD 2211 and 2211-JDK21, according to SAP’s advisory. Authorized Re

    @XQOPTRX

    15 Aug 2026

    32 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  17. CyberSec Daily ✓ · 🚨 Vulnerability · August 15, 2026 🎯 Critical SAP Commerce Cloud flaw targeted only days after patch release Researchers are detecting exploitation attempts against CVE-2026-58231, a maximum-severity vulnerability in SAP Commerce Cloud’s Data Hub A

    @XQOPTRX

    15 Aug 2026

    38 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  18. A critical SAP Commerce Cloud vulnerability (CVE-2026-58231, CVSS 10.0) is being actively exploited just days after a patch. This underscores the narrow window for response. RootCrak's autonomous scanning is built to identify such high-risk exposures quickly, helping https://t.co

    @ro0TCr4k

    15 Aug 2026

    58 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  19. SAP Commerce Cloud CVE-2026-58231 Targeted in Exploitation Attempts Days After Patch https://t.co/0KiATbrrid

    @PVynckier

    15 Aug 2026

    77 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  20. SAP issued its August 2026 Patch Tuesday release with 28 advisories, four rated Critical. CVE-2026-58231 in SAP Commerce Cloud Data Hub Adapter scores CVSS 10.0 due to authorization bypass. Two code injection flaws (CVE-2026-44772, CVE-2026-44758) affect SAP Manufacturing

    @WorldCyberNewsX

    13 Aug 2026

    4 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  21. SAPの定例セキュリティ更新。SAP Commerce CloudのData Hub AdapterにおけるCVE-2026-58231がCVSSスコア10。SAP Manufacturing Integration and IntelligenceのCVE-2026-44772がCVSSスコア9.9。NetWeaverのメモリ破壊CVE-2026-34265がCVSSスコア9.8。 https://

    @__kokumoto

    12 Aug 2026

    602 Impressions

    0 Retweets

    0 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  22. SAPは8月11日、2026年8月のPatch Dayで28件の新たなセキュリティノートを公開した。SAP Commerce Cloudの認可不備CVE-2026-58231を筆頭に、SAP MIIやNetWeaverなどでコード実行につながる重大な脆弱性が修正された。 CVE-2026-5823

    @yousukezan

    11 Aug 2026

    1240 Impressions

    0 Retweets

    1 Like

    2 Bookmarks

    0 Replies

    0 Quotes

References

Sources include official advisories and independent security research.