
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-58231 is a critical code injection vulnerability in SAP Commerce Cloud (Data Hub Adapter) that allows unauthenticated remote attackers to execute arbitrary code by abusing a default authentication client and submitting specially crafted input to functions lacking sufficient validation. It was published on August 11, 2026, and affects SAP Commerce Cloud versions COM_CLOUD 2211 and 2211-JDK21. The vulnerability carries a maximum CVSS v3.1 base score of 10.0 (Critical) with a changed scope, reflecting its potential to compromise components beyond the directly affected system (GitHub Advisory, ENISA EUVD).
The root cause is classified as CWE-94 (Improper Control of Generation of Code / Code Injection): the application constructs code segments using externally-influenced input without properly neutralizing special elements that could alter code behavior (GitHub Advisory). The attack vector is network-accessible with no authentication required, no user interaction needed, and low attack complexity — the attacker exploits a default authentication client present in the Data Hub Adapter component to submit malicious payloads to insufficiently validated functions. The changed scope indicates that successful exploitation can affect resources beyond the vulnerable component itself, enabling compromise of internal SAP Commerce Cloud components (ENISA EUVD). No public proof-of-concept code has been identified as of the time of disclosure (Feedly).
Successful exploitation results in high impact across all three security dimensions: confidentiality, integrity, and availability. An unauthenticated remote attacker can execute arbitrary code on the SAP Commerce Cloud application, potentially gaining full control of the affected system and compromising internal components such as the Data Hub Adapter. The changed scope means the attacker's reach extends beyond the directly vulnerable component, enabling lateral movement into connected SAP systems, data exfiltration of sensitive commerce and customer data, and disruption of business-critical e-commerce operations (GitHub Advisory, SecurityWeek).
As of disclosure, there is no public proof-of-concept exploit and no confirmed evidence of in-the-wild exploitation (Feedly). The NVD SSVC assessment classifies the vulnerability as automatable with total technical impact, meaning exploitation could be scripted at scale with no manual steps required. The EPSS score is currently 0.0, reflecting the early stage of the vulnerability's public lifecycle. The vulnerability has not been listed in the CISA Known Exploited Vulnerabilities (KEV) catalog as of the time of this report. Despite the absence of active exploitation, the maximum CVSS score and zero-authentication requirement make it a high-priority target (ENISA EUVD, CSO Online).
curl, wget, nc); unexpected process execution under the SAP service account.SAP has released a security patch addressing CVE-2026-58231, documented in SAP Security Note 3771065, available via the SAP Support Portal. Organizations should apply this patch immediately given the maximum severity rating and zero-authentication exploitation requirement (GitHub Advisory, SAP Security Patch Day). As interim mitigations, administrators should review and restrict or disable default authentication client configurations in the Data Hub Adapter, implement network-level controls to limit access to Commerce Cloud endpoints to trusted IP ranges, and enforce input validation and sanitization for all functions processing user-supplied data. Monitor authentication logs for suspicious activity targeting default credentials or crafted inputs.
The vulnerability received significant media coverage upon disclosure on SAP's August 2026 Patch Day. SecurityWeek and The Hacker News both reported on the flaw, highlighting its maximum CVSS score and the risk of unauthenticated code execution (SecurityWeek, The Hacker News). Heise described SAP Commerce Cloud as "fully compromisable" in its patch day coverage (Heise). CSO Online contextualized it alongside other August 2026 Patch Tuesday disclosures, noting its maximum severity as a standout item (CSO Online). Community discussion on Reddit's r/SecOpsDaily and Mastodon/Infosec.exchange reflected urgency around patching, given the zero-authentication requirement and broad enterprise use of SAP Commerce Cloud.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."