CVE-2026-58231: Critical Vulnerability in SAP Commerce Cloud (CVSS 10.0)
This text was generated using artificial intelligence (AI).On August 11, 2026, SAP, in accordance with SAP Security Note 3771065 a critical vulnerability in the SAP Commerce Cloud disclosed, identified by the identifier CVE-2026-58231 and the highest possible CVSS score of 10.0 has been assessed. The vulnerability allows unauthenticated attackers to execute arbitrary code over the network (Remote Code Execution, RCE) and thereby gain complete control over affected systems. This poses a significant risk to the confidentiality, integrity, and availability of e-commerce platforms.
The cause of CVE-2026-58231 lies in insufficient input validation in certain functions of SAP Commerce Cloud. An attacker can exploit a default-configured authentication client to send specially crafted data to the system. Since no credentials are required for this, the attack can be carried out from any location on the Internet.
A successful exploit results in code being executed within the context of the application. This allows attackers to exfiltrate, manipulate, or delete data; cripple the application; or use the compromised system as a launching pad for further attacks on internal corporate networks.
Risk Assessment According to CVSS 3.1
The CVSS score CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H illustrates the high risk:
Attack Vector: Network (AV:N): The vulnerability can be exploited over the network.
Attack Complexity: Low (AC:L): The attack does not require any complex prerequisites.
Privileges Required: None (PR:N): An attacker does not need any user accounts or privileges.
User Interaction: None (UI:N): No interaction by a legitimate user is required.
Scope: Changed (S:C): A security breach can affect other parts of the system beyond the affected component.
Confidentiality, Integrity, Availability: High (C:H, I:H, A:H): The attack could result in a complete loss of confidentiality, integrity, and availability.
For organizations subject to the NIS 2 Directive, a significant security incident related to this vulnerability may trigger a reporting obligation under Article 23 of the NIS 2 Directive. In addition, if the personal data of EU citizens is affected, the 72-hour reporting obligation under Article 33 of the GDPR to the competent data protection authority applies.
For KRITIS operators and companies in the German retail and e-commerce sectors that fall under the NIS 2 Implementation Act (NIS2UmsuCG), the BSI generally recommends immediately assessing critical vulnerabilities using CVSS 10.0 and implementing appropriate protective measures. If SAP Commerce Cloud instances are part of the production infrastructure, the risk assessment should be documented immediately.
Recommended Actions
Since, at the time of publication, according to SAP Security Note 3771065 Since no security updates were available, proactive measures to identify and secure the system are essential.
Immediate measures:
Identification: Identify all publicly and internally accessible instances of SAP Commerce Cloud in your IT infrastructure.
Exam: Verify whether the affected versions (2211-jdk21, com_cloud_2211) are in use.
Monitoring: Implement enhanced monitoring of the affected systems to detect suspicious activity.
Long-term measures:
Patch Management: Follow SAP's security guidelines at SAP Security Note 3771065 and install any patches provided immediately.
Vulnerability Monitoring: Establish a process for continuously monitoring your external attack surface to identify exposed systems early on.
Vendor Risk Management: Systematically assess the security status of your critical service providers and suppliers.
Visibility of the Attack Surface with LocateRisk
Vulnerabilities such as CVE-2026-58231 underscore the need for a comprehensive and up-to-date overview of the external attack surface. SAP Commerce Cloud instances are often operated under customer-owned domains (e.g.,. shop.company.de) and, if they are not centrally tracked, can become undetected shadow IT—that is, systems that are missing from the official asset inventory and are therefore excluded from any patching process.
LocateRisk supports companies by External Attack Surface Management (EASM) to build and maintain a comprehensive inventory of all publicly accessible IT systems. The platform identifies exposed applications—including forgotten subdomains and unmanaged cloud assets—and enables security teams to detect potentially vulnerable systems before or immediately after a critical vulnerability becomes known. Through continuous monitoring, the time between a system’s accidental exposure and its detection can be significantly reduced. This creates the necessary transparency to prioritize and mitigate risks in a targeted manner.
Am I affected?
This affects the `sap_se sap_commerce_cloud_data_hub_adapter` in the versions listed above. If you want to know whether the `sap_se sap_commerce_cloud_data_hub_adapter` is even visible in your own externally accessible infrastructure, you can use the CVE Quick Check Use the tool at the end of this article: It shows exposed systems and the software that is visible from the outside.
It is not always possible to determine the specific version that has been installed based on external information alone—the key factor remains verification against the manufacturer's advisory.
CVE-2026-58231 is a vulnerability in SAP Commerce Cloud that allows an unauthenticated attacker to execute arbitrary code over the network (Remote Code Execution). It receives the highest possible CVSS score of 10.0 because no authentication or user interaction is required, and a successful exploit has a complete impact on the application’s confidentiality, integrity, and availability.
According to SAP Security Note 3771065, the versions are 2211-jdk21 and com_cloud_2211 Affected by CVE-2026-58231. As of the publication date of August 11, 2026, no patched versions were available.
Affected companies should first take inventory of all instances of SAP Commerce Cloud in the affected versions and restrict their network accessibility wherever possible. In addition, it is recommended to increase monitoring for suspicious activity and to regularly check the SAP Security Note 3771065 for newly released patches or workarounds.
As of August 11, 2026. This post is intended for general informational purposes only and does not constitute legal, security, or operational advice in specific cases. The security situation and patch availability may have changed since publication; the linked vendor advisory is always authoritative. Despite careful research, we do not guarantee that the information is up-to-date, accurate, or complete.
CVE Quick Check
In just a few minutes, check whether there are any indications of a current CVE on your externally visible attack surface.
A rough estimate in just a few minutes via email.
Learn more during a free consultation with a LocateRisk consultant.
You'll receive this by email
companyYour Company, LLC
Verified CVECVE-2024-3094
Passive Assessment
Information About the CVENotes found
Want to find out more, book a demo or simply exchange ideas? We look forward to hearing from you!
We use cookies to optimize our website and our service.
Functional
Always active
Technical storage or access is strictly necessary for the lawful purpose of enabling the use of a particular service expressly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a message over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that have not been requested by the subscriber or user.
Statistics
The technical storage or access, which is carried out exclusively for statistical purposes.Technical storage or access used solely for anonymous statistical purposes. Without a subpoena, the voluntary consent of your Internet service provider, or additional records from third parties, information stored or accessed for this purpose alone generally cannot be used to identify you.
Marketing
Technical storage or access is necessary to create user profiles, to send advertisements, or to track the user on a website or across multiple websites for similar marketing purposes.