CVE-2026-58231

Critical10.0Published on August 11, 2026

SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation. Successful exploitation could enable arbitrary code execution and compromise internal components, resulting in high impact on confidentiality, integrity, and availability of the application.

Early warning: exploitation observed

  • Exploitation observed since Aug 14, 2026
  • Not yet in the official CISA catalogue
  • First attack observed 3 days after disclosure

Source: VulnCheck KEV · Sep 3, 2026 Aug 15, 2026 Aug 14, 2026 Aug 14, 2026

CVSS score10.0 / 10CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Weakness type (CWE)CWE-94

Related articles

This product uses the NVD API but is not endorsed or certified by the NVD.

CVE database