CVE-2026-58231
SAP Commerce Cloud vulnerability analysis and mitigation

Overview

CVE-2026-58231 is a maximum-severity code injection vulnerability in SAP Commerce Cloud (Data Hub Adapter) that allows unauthenticated remote attackers to execute arbitrary code by abusing a default authentication client and submitting specially crafted input to insufficiently validated functions. It affects SAP Commerce Cloud versions COM_CLOUD 2211 and 2211-JDK21. The vulnerability was published on August 11, 2026, with a patch released the same day. It carries a CVSS v3.1 base score of 10.0 (Critical) (GitHub Advisory, ENISA EUVD).

Technical details

The root cause is classified as CWE-94 (Improper Control of Generation of Code / Code Injection): SAP Commerce Cloud's Data Hub Adapter exposes a default authentication client that does not enforce proper credential controls, allowing unauthenticated network access to functions that lack sufficient input validation. An attacker can submit specially crafted payloads to these exposed endpoints, causing the application to interpret and execute attacker-controlled code. No user interaction or privileges are required, and the scope is changed — meaning successful exploitation can impact components beyond the vulnerable service itself. The attack is fully automatable over the network (GitHub Advisory, SAP Security Note 3771065).

Impact

Successful exploitation grants an unauthenticated attacker arbitrary code execution on the SAP Commerce Cloud server, with high impact on confidentiality, integrity, and availability. Attackers can compromise internal application components, exfiltrate sensitive e-commerce and customer data, modify or destroy application data, and potentially pivot laterally to connected backend systems. The changed scope means the blast radius extends beyond the directly vulnerable component, making this a systemic risk for organizations running SAP Commerce Cloud (GitHub Advisory, BleepingComputer).

Exploitability

Active exploitation in the wild was confirmed within approximately three days of the patch release (by August 14, 2026), with multiple security sources reporting exploitation attempts (BleepingComputer, Security Affairs). The Lazarus Group (North Korea-linked APT) has been attributed as one of the threat actors exploiting this vulnerability, according to FireCompass (Feedly Intelligence). A public scanner/PoC repository exists on GitHub (HORKimhab/CVE-2026-58231), though it is classified as a detection/scanner tool rather than a weaponized exploit; no confirmed public full exploit code was available at time of reporting (GitHub PoC). The EPSS score is approximately 1.71% (76th percentile) per the GitHub Advisory, and the vulnerability is listed as automatable with total technical impact. CISA KEV catalog status was not confirmed in available sources at time of writing.

Exploitation steps

  1. Reconnaissance: Identify internet-facing SAP Commerce Cloud (Data Hub Adapter) instances running versions COM_CLOUD 2211 or 2211-JDK21 using tools such as Shodan, Censys, or FOFA, searching for SAP Commerce Cloud service banners or known API endpoints.
  2. Identify default authentication client: Locate the exposed Data Hub Adapter endpoint that uses a default (unauthenticated or weakly authenticated) OAuth/authentication client — this client does not require valid credentials for access.
  3. Craft malicious payload: Construct a specially crafted HTTP request containing a code injection payload targeting the insufficiently validated input functions exposed via the default authentication client endpoint.
  4. Submit payload: Send the crafted request to the vulnerable endpoint without providing any authentication credentials, exploiting the default client's lack of access controls.
  5. Achieve arbitrary code execution: The injected code is interpreted and executed server-side by the SAP Commerce Cloud application, enabling the attacker to run OS commands, deploy web shells, exfiltrate data, or establish persistence on the compromised host (GitHub Advisory, BleepingComputer).

Indicators of compromise

  • Network: Unexpected or anomalous HTTP/HTTPS requests to SAP Commerce Cloud Data Hub Adapter endpoints from external or unknown IP addresses, particularly requests that do not include valid authentication tokens; outbound connections from the SAP Commerce Cloud server to unknown external IPs (potential C2 communication).
  • Logs: SAP Commerce Cloud application logs showing unauthenticated access attempts or successful requests to Data Hub Adapter functions using the default authentication client; error messages or stack traces related to code evaluation or injection in application logs; authentication logs showing use of default client credentials.
  • File System: Unexpected new files (web shells, scripts, binaries) written to the SAP Commerce Cloud installation or web root directories; modification timestamps on application files inconsistent with normal deployment activity.
  • Process: Unusual child processes spawned by the SAP Commerce Cloud Java process (e.g., sh, bash, cmd.exe, curl, wget, powershell); unexpected network connections initiated by the Java application process.
  • Behavioral: Sudden spikes in CPU or memory usage on the SAP Commerce Cloud server; new scheduled tasks or cron jobs created under the application service account (BleepingComputer, Security Affairs).

Mitigation and workarounds

SAP released a security patch on August 11, 2026, via SAP Security Note 3771065, addressing this vulnerability in SAP Commerce Cloud COM_CLOUD 2211 and 2211-JDK21. Organizations should apply this patch immediately as the highest priority action (SAP Security Note, SAP Patch Day). As interim mitigations where patching is not immediately possible: restrict network access to SAP Commerce Cloud Data Hub Adapter endpoints at the firewall or network perimeter level; disable or reconfigure the default authentication client to require strong credentials; and monitor authentication and application logs for signs of exploitation. Given confirmed active exploitation within days of patch release, emergency patching is strongly recommended (Canadian CCCS Advisory, CSA Singapore Alert).

Community reactions

The vulnerability generated significant coverage across the security community, with BleepingComputer, The Hacker News, SecurityWeek, SC World, Cybersecurity Dive, and Heise all reporting on active exploitation within days of the patch (BleepingComputer, SecurityWeek). Government CERTs including Canada's CCCS and Singapore's CSA issued advisories urging immediate patching (Canadian CCCS Advisory, CSA Singapore Alert). Security researchers on social media (Mastodon, Bluesky, Reddit) highlighted the extremely short disclosure-to-exploitation window of approximately three days as particularly alarming. The attribution to Lazarus Group drew additional attention from the threat intelligence community, with FireCompass and others noting the APT's rapid weaponization of the flaw (Security Affairs).

Additional resources


SourceThis report was generated using AI

Related SAP Commerce Cloud vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-58231CRITICAL10
  • SAP Commerce Cloud logoSAP Commerce Cloud
  • cpe:2.3:a:sap:commerce_cloud
NoNoAug 11, 2026
CVE-2026-34263CRITICAL9.6
  • SAP Commerce Cloud logoSAP Commerce Cloud
  • cpe:2.3:a:sap:commerce_cloud
NoNoMay 12, 2026
CVE-2024-33003CRITICAL9.1
  • SAP Commerce Cloud logoSAP Commerce Cloud
  • cpe:2.3:a:sap:commerce_cloud
NoNoAug 13, 2024
CVE-2026-23684MEDIUM5.9
  • SAP Commerce Cloud logoSAP Commerce Cloud
  • cpe:2.3:a:sap:commerce_cloud
NoNoFeb 10, 2026
CVE-2026-24321MEDIUM5.3
  • SAP Commerce Cloud logoSAP Commerce Cloud
  • cpe:2.3:a:sap:commerce_cloud
NoNoFeb 10, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management