Description
SAP Commerce Cloud allows an unauthenticated
attacker to abuse a default authentication client and submit specially crafted
input to certain functions lacking sufficient validation. Successful
exploitation could enable arbitrary code execution and compromise internal
components, resulting in high impact on confidentiality, integrity, and
availability of the application.
Published: 2026-08-11
Score: 10 Critical
EPSS: 1.7% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

SAP Commerce Cloud allows an unauthenticated attacker to exploit a default authentication client and send specially crafted data to functions that lack proper validation. This flaw is a code injection vulnerability (CWE-94) that can lead to arbitrary code execution and compromise the confidentiality, integrity, and availability of internal components.

Affected Systems

The affected product is SAP Commerce Cloud Data Hub Adapter as identified by SAP SE. No specific version numbers are listed in the available data, so all releases using the default authentication client are potentially vulnerable. The SAP Note 3771065 and the SAP Security Patch Day URL provide additional context for affected deployments.

Risk and Exploitability

The CVSS score of 10 indicates a critical severity. Because the EPSS score is not available, the exploitation likelihood is unknown, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote and unauthenticated, inferred from the description that the attacker can submit input without prior authentication. Successful exploitation would enable the attacker to run arbitrary code within the application context.

Generated by OpenCVE AI on August 11, 2026 at 11:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the SAP security patch for CVE-2026-58231 as detailed in SAP Note 3771065.
  • Disable or restrict the default authentication client to prevent unauthenticated access to vulnerable endpoints.
  • Implement input validation and sanitization on all functions that process external data to mitigate code injection.
  • Check for any additional security patches or recommendations from SAP and apply them promptly.

Generated by OpenCVE AI on August 11, 2026 at 11:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 11 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Sap Se sap Commerce Cloud Data Hub Adapter
Vendors & Products Sap Se sap Commerce Cloud Data Hub Adapter

Tue, 11 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 10:45:00 +0000

Type Values Removed Values Added
Description SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation. Successful exploitation could enable arbitrary code execution and compromise internal components, resulting in high impact on confidentiality, integrity, and availability of the application.
Title Improper Authorization in SAP Commerce Cloud (Data Hub Adapter)
First Time appeared Sap Se
Sap Se sap Commerce Cloud Data Hub Adapter
Weaknesses CWE-94
CPEs cpe:2.3:a:sap_se:sap_commerce_cloud_data_hub_adapter_:2211-jdk21:*:*:*:*:*:*:*
cpe:2.3:a:sap_se:sap_commerce_cloud_data_hub_adapter_:com_cloud_2211:*:*:*:*:*:*:*
Vendors & Products Sap Se
Sap Se sap Commerce Cloud Data Hub Adapter
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Sap Se Sap Commerce Cloud Data Hub Adapter Sap Commerce Cloud Data Hub Adapter
cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published:

Updated: 2026-08-12T03:59:57.112Z

Reserved: 2026-06-29T19:34:28.222Z

Link: CVE-2026-58231

cve-icon Vulnrichment

Updated: 2026-08-11T14:26:17.960Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-11T11:17:15.390

Modified: 2026-08-17T15:39:24.573

Link: CVE-2026-58231

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-11T14:19:37Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')