CVE-2026-58231
Received Received - Intake

Arbitrary Code Execution in SAP Commerce Cloud

Vulnerability report for CVE-2026-58231, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-11

Last updated on: 2026-08-11

Assigner: SAP SE

Description

SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation. Successful exploitation could enable arbitrary code execution and compromise internal components, resulting in high impact on confidentiality, integrity, and availability of the application.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-11
Last Modified
2026-08-11
Generated
2026-08-11
AI Q&A
2026-08-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
sap commerce_cloud *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-94 The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in SAP Commerce Cloud allows an unauthenticated attacker to exploit a default authentication client by submitting specially crafted input to unvalidated functions. Successful exploitation could lead to arbitrary code execution and compromise internal components, resulting in high impact on confidentiality, integrity, and availability of the application.

Detection Guidance

Detecting this vulnerability requires checking for exposed SAP Commerce Cloud instances with default authentication clients. Monitor network traffic for unusual requests to SAP endpoints. Use SAP's official tools like SAP Solution Manager or SAP Focused Insights to scan for misconfigurations. Check logs for failed authentication attempts or unexpected code execution patterns.

Impact Analysis

This vulnerability can lead to unauthorized access, data breaches, system compromise, and potential disruption of services. Attackers could gain control over internal components, steal sensitive data, or manipulate system operations, causing significant operational and reputational damage.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR, HIPAA, and other regulations due to unauthorized data access, breaches of confidentiality, or integrity violations. Organizations may face legal penalties, fines, and reputational harm for failing to protect sensitive data adequately.

Mitigation Strategies

Apply the official SAP patch or update referenced in SAP Note 3771065 immediately. Disable or restrict access to the default authentication client until patched. Monitor network traffic for unusual activity targeting SAP Commerce Cloud components.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-58231. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart