Junglewise Threat Intelligence

CVE-2026-58231: SAP Commerce Cloud unauthenticated code execution via default authentication

CVE-2026-58231 · Severity: critical · CVSS 10 · Published 2026-08-11

Technologies: SAP Commerce Cloud. Vendors: SAP.

Executive brief

SAP Commerce Cloud is a cloud-based e-commerce platform used by businesses to manage online storefronts and customer transactions. An unauthenticated attacker can exploit a default authentication client and craft malicious input to execute arbitrary code on the platform, compromising customer data, order information, and business operations.

Technical details

This vulnerability stems from insufficient input validation in certain functions within SAP Commerce Cloud that are reachable via a default authentication client without authentication. By submitting specially crafted input, an attacker can bypass security controls and achieve remote code execution. The vulnerability affects internal components and allows an unauthenticated, network-based attacker to compromise confidentiality, integrity, and availability. No authentication is required; the attack vector is purely network-based. A patch has been released as part of SAP Security Patch Day on August 11, 2026.

Affected products

  • SAP Commerce Cloud

Timeline

  • 2026-08-11: disclosed

References

Related threats