
PEACH
Un cadre d’isolation des locataires
CVE-2026-58231 is a critical code injection vulnerability in SAP Commerce Cloud (Data Hub Adapter) that allows unauthenticated remote attackers to execute arbitrary code by abusing a default authentication client and submitting specially crafted input to functions lacking sufficient validation. It was published on August 11, 2026, and affects SAP Commerce Cloud versions COM_CLOUD 2211 and 2211-JDK21. The vulnerability carries a maximum CVSS v3.1 base score of 10.0 (Critical) with a changed scope, reflecting its potential to compromise components beyond the directly affected system (GitHub Advisory, ENISA EUVD).
The root cause is classified as CWE-94 (Improper Control of Generation of Code / Code Injection): the application constructs code segments using externally-influenced input without properly neutralizing special elements that could alter code behavior (GitHub Advisory). The attack vector is network-accessible with no authentication required, no user interaction needed, and low attack complexity — the attacker exploits a default authentication client present in the Data Hub Adapter component to submit malicious payloads to insufficiently validated functions. The changed scope indicates that successful exploitation can affect resources beyond the vulnerable component itself, enabling compromise of internal SAP Commerce Cloud components (ENISA EUVD). No public proof-of-concept code has been identified as of the time of disclosure (Feedly).
Successful exploitation results in high impact across all three security dimensions: confidentiality, integrity, and availability. An unauthenticated remote attacker can execute arbitrary code on the SAP Commerce Cloud application, potentially gaining full control of the affected system and compromising internal components such as the Data Hub Adapter. The changed scope means the attacker's reach extends beyond the directly vulnerable component, enabling lateral movement into connected SAP systems, data exfiltration of sensitive commerce and customer data, and disruption of business-critical e-commerce operations (GitHub Advisory, SecurityWeek).
As of disclosure, there is no public proof-of-concept exploit and no confirmed evidence of in-the-wild exploitation (Feedly). The NVD SSVC assessment classifies the vulnerability as automatable with total technical impact, meaning exploitation could be scripted at scale with no manual steps required. The EPSS score is currently 0.0, reflecting the early stage of the vulnerability's public lifecycle. The vulnerability has not been listed in the CISA Known Exploited Vulnerabilities (KEV) catalog as of the time of this report. Despite the absence of active exploitation, the maximum CVSS score and zero-authentication requirement make it a high-priority target (ENISA EUVD, CSO Online).
curl, wget, nc); unexpected process execution under the SAP service account.SAP has released a security patch addressing CVE-2026-58231, documented in SAP Security Note 3771065, available via the SAP Support Portal. Organizations should apply this patch immediately given the maximum severity rating and zero-authentication exploitation requirement (GitHub Advisory, SAP Security Patch Day). As interim mitigations, administrators should review and restrict or disable default authentication client configurations in the Data Hub Adapter, implement network-level controls to limit access to Commerce Cloud endpoints to trusted IP ranges, and enforce input validation and sanitization for all functions processing user-supplied data. Monitor authentication logs for suspicious activity targeting default credentials or crafted inputs.
The vulnerability received significant media coverage upon disclosure on SAP's August 2026 Patch Day. SecurityWeek and The Hacker News both reported on the flaw, highlighting its maximum CVSS score and the risk of unauthenticated code execution (SecurityWeek, The Hacker News). Heise described SAP Commerce Cloud as "fully compromisable" in its patch day coverage (Heise). CSO Online contextualized it alongside other August 2026 Patch Tuesday disclosures, noting its maximum severity as a standout item (CSO Online). Community discussion on Reddit's r/SecOpsDaily and Mastodon/Infosec.exchange reflected urgency around patching, given the zero-authentication requirement and broad enterprise use of SAP Commerce Cloud.
Source: Ce rapport a été généré à l’aide de l’IA
Évaluation gratuite des vulnérabilités
Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.
Obtenez une démo personnalisée
"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."