
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-58231 is a maximum-severity code injection vulnerability in SAP Commerce Cloud (Data Hub Adapter) that allows unauthenticated remote attackers to execute arbitrary code by abusing a default authentication client and submitting specially crafted input to insufficiently validated functions. It affects SAP Commerce Cloud versions COM_CLOUD 2211 and 2211-JDK21. The vulnerability was published on August 11, 2026, with a patch released the same day. It carries a CVSS v3.1 base score of 10.0 (Critical) (GitHub Advisory, ENISA EUVD).
The root cause is classified as CWE-94 (Improper Control of Generation of Code / Code Injection): SAP Commerce Cloud's Data Hub Adapter exposes a default authentication client that does not enforce proper credential controls, allowing unauthenticated network access to functions that lack sufficient input validation. An attacker can submit specially crafted payloads to these exposed endpoints, causing the application to interpret and execute attacker-controlled code. No user interaction or privileges are required, and the scope is changed — meaning successful exploitation can impact components beyond the vulnerable service itself. The attack is fully automatable over the network (GitHub Advisory, SAP Security Note 3771065).
Successful exploitation grants an unauthenticated attacker arbitrary code execution on the SAP Commerce Cloud server, with high impact on confidentiality, integrity, and availability. Attackers can compromise internal application components, exfiltrate sensitive e-commerce and customer data, modify or destroy application data, and potentially pivot laterally to connected backend systems. The changed scope means the blast radius extends beyond the directly vulnerable component, making this a systemic risk for organizations running SAP Commerce Cloud (GitHub Advisory, BleepingComputer).
Active exploitation in the wild was confirmed within approximately three days of the patch release (by August 14, 2026), with multiple security sources reporting exploitation attempts (BleepingComputer, Security Affairs). The Lazarus Group (North Korea-linked APT) has been attributed as one of the threat actors exploiting this vulnerability, according to FireCompass (Feedly Intelligence). A public scanner/PoC repository exists on GitHub (HORKimhab/CVE-2026-58231), though it is classified as a detection/scanner tool rather than a weaponized exploit; no confirmed public full exploit code was available at time of reporting (GitHub PoC). The EPSS score is approximately 1.71% (76th percentile) per the GitHub Advisory, and the vulnerability is listed as automatable with total technical impact. CISA KEV catalog status was not confirmed in available sources at time of writing.
sh, bash, cmd.exe, curl, wget, powershell); unexpected network connections initiated by the Java application process.SAP released a security patch on August 11, 2026, via SAP Security Note 3771065, addressing this vulnerability in SAP Commerce Cloud COM_CLOUD 2211 and 2211-JDK21. Organizations should apply this patch immediately as the highest priority action (SAP Security Note, SAP Patch Day). As interim mitigations where patching is not immediately possible: restrict network access to SAP Commerce Cloud Data Hub Adapter endpoints at the firewall or network perimeter level; disable or reconfigure the default authentication client to require strong credentials; and monitor authentication and application logs for signs of exploitation. Given confirmed active exploitation within days of patch release, emergency patching is strongly recommended (Canadian CCCS Advisory, CSA Singapore Alert).
The vulnerability generated significant coverage across the security community, with BleepingComputer, The Hacker News, SecurityWeek, SC World, Cybersecurity Dive, and Heise all reporting on active exploitation within days of the patch (BleepingComputer, SecurityWeek). Government CERTs including Canada's CCCS and Singapore's CSA issued advisories urging immediate patching (Canadian CCCS Advisory, CSA Singapore Alert). Security researchers on social media (Mastodon, Bluesky, Reddit) highlighted the extremely short disclosure-to-exploitation window of approximately three days as particularly alarming. The attribution to Lazarus Group drew additional attention from the threat intelligence community, with FireCompass and others noting the APT's rapid weaponization of the flaw (Security Affairs).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."