CVE-2026-58231: Critical Vulnerability in SAP Commerce Cloud (CVSS 10.0)
This text was generated using artificial intelligence (AI).Update August 11, 2026: SAP has released security updates for CVE-2026-58231. Affected versions COM_CLOUD 2211 and COM_CLOUD 2211-JDK21 can be patched according to the fixed release levels documented in SAP Note 3771065. See below for details.
On August 11, 2026, SAP, in accordance with SAP Security Note 3771065 a critical vulnerability in the SAP Commerce Cloud disclosed, identified by the identifier CVE-2026-58231 and the highest possible CVSS score of 10.0 has been assessed. The vulnerability allows unauthenticated attackers to execute arbitrary code over the network (Remote Code Execution, RCE) and thereby gain complete control over affected systems. This poses a significant risk to the confidentiality, integrity, and availability of e-commerce platforms.
Patch: Available for COM_CLOUD 2211 and COM_CLOUD 2211-JDK21
Technical Background of the Vulnerability
The cause of CVE-2026-58231 lies in insufficient input validation in certain functions of SAP Commerce Cloud. An attacker can exploit a default-configured authentication client to send specially crafted data to the system. Since no credentials are required for this, the attack can be carried out from any location on the Internet.
A successful exploit results in code being executed within the context of the application. This allows attackers to exfiltrate, manipulate, or delete data; cripple the application; or use the compromised system as a launching pad for further attacks on internal corporate networks.
Risk Assessment According to CVSS 3.1
The CVSS score CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H illustrates the high risk:
Attack Vector: Network (AV:N): The vulnerability can be exploited over the network.
Attack Complexity: Low (AC:L): The attack does not require any complex prerequisites.
Privileges Required: None (PR:N): An attacker does not need any user accounts or privileges.
User Interaction: None (UI:N): No interaction by a legitimate user is required.
Scope: Changed (S:C): A security breach can affect other parts of the system beyond the affected component.
Confidentiality, Integrity, Availability: High (C:H, I:H, A:H): The attack could result in a complete loss of confidentiality, integrity, and availability.
For organizations subject to the NIS 2 Directive, a significant security incident related to this vulnerability may trigger a reporting obligation under Article 23 of the NIS 2 Directive. In addition, if the personal data of EU citizens is affected, the 72-hour reporting obligation under Article 33 of the GDPR to the competent data protection authority applies.
For KRITIS operators and companies in the German retail and e-commerce sectors that fall under the NIS 2 Implementation Act (NIS2UmsuCG), the BSI generally recommends immediately assessing critical vulnerabilities using CVSS 10.0 and implementing appropriate protective measures. If SAP Commerce Cloud instances are part of the production infrastructure, the risk assessment should be documented immediately.
Available Security Updates
SAP has released security updates for CVE-2026-58231. According to SAP Security Note 3771065 Fixed release levels are available for the affected versions, COM_CLOUD 2211 and COM_CLOUD 2211-JDK21, which address the vulnerability.
Organizations using one of the affected versions should apply the patch versions documented in the SAP Note immediately. The exact release level information and installation instructions are provided in the official SAP Security Note.
Recommended Actions
Immediate measures:
Identification: Identify all publicly and internally accessible instances of SAP Commerce Cloud in your IT infrastructure.
Exam: Verify whether the affected versions (COM_CLOUD 2211, COM_CLOUD 2211-JDK21) are in use.
Patch Installation: Install the files in SAP Security Note 3771065 documented fixed release levels immediately.
Monitoring: Implement enhanced monitoring of the affected systems to detect suspicious activity, particularly during the transition period until the patch is fully implemented.
Long-term measures:
Patch Management: Establish a structured process for the timely implementation of SAP security updates and continuously monitor SAP security advisories.
Vulnerability Monitoring: Establish a process for continuously monitoring your external attack surface to identify exposed systems early on.
Vendor Risk Management: Systematically assess the security status of your critical service providers and suppliers.
Visibility of the Attack Surface with LocateRisk
Vulnerabilities such as CVE-2026-58231 underscore the need for a comprehensive and up-to-date overview of the external attack surface. SAP Commerce Cloud instances are often operated under customer-owned domains (e.g.,. shop.company.de) and, if they are not centrally tracked, can become undetected shadow IT—that is, systems that are missing from the official asset inventory and are therefore excluded from any patching process.
LocateRisk supports companies by External Attack Surface Management (EASM) to build and maintain a comprehensive inventory of all publicly accessible IT systems. The platform identifies exposed applications—including forgotten subdomains and unmanaged cloud assets—and enables security teams to detect potentially vulnerable systems before or immediately after a critical vulnerability becomes known. Through continuous monitoring, the time between a system’s accidental exposure and its detection can be significantly reduced. This creates the necessary transparency to prioritize and mitigate risks in a targeted manner.
Am I affected?
This affects the `sap_se sap_commerce_cloud_data_hub_adapter` in the versions listed above. If you want to know whether the `sap_se sap_commerce_cloud_data_hub_adapter` is even visible in your own externally accessible infrastructure, you can use the CVE Quick Check Use the tool at the end of this article: It shows exposed systems and the software that is visible from the outside.
It is not always possible to determine the specific version that has been installed based on external information alone—the key factor remains verification against the manufacturer's advisory.
CVE-2026-58231 is a vulnerability in SAP Commerce Cloud that allows an unauthenticated attacker to execute arbitrary code over the network (Remote Code Execution). It receives the highest possible CVSS score of 10.0 because no authentication or user interaction is required, and a successful exploit has a complete impact on the application’s confidentiality, integrity, and availability.
According to SAP Security Note 3771065, versions COM_CLOUD 2211 and COM_CLOUD 2211-JDK21 are affected by CVE-2026-58231. Security updates are available for both versions.
Yes, SAP has released security updates. According to SAP Security Note 3771065 Fixed release levels are available for COM_CLOUD 2211 and COM_CLOUD 2211-JDK21 that address the vulnerability. Affected organizations should install these updates immediately.
Affected companies should first take inventory of all instances of SAP Commerce Cloud in the affected versions and immediately apply the security updates documented in SAP Security Note 3771065. Until the patches have been fully implemented, it is recommended to increase monitoring for suspicious activity and, where possible, restrict network accessibility.
As of August 12, 2026. This article is intended for general informational purposes only and does not constitute legal, security, or operational advice in specific cases. The security situation and patch availability may have changed since publication; the linked vendor advisory is always authoritative. Despite careful research, we do not guarantee that the information is up-to-date, accurate, or complete.
CVE Quick Check
In just a few minutes, check whether there are any indications of a current CVE on your externally visible attack surface.
A rough estimate in just a few minutes via email.
Learn more during a free consultation with a LocateRisk consultant.
You'll receive this by email
companyYour Company, LLC
Verified CVECVE-2026-58231
Passive Assessment
Information About the CVEfound or not found
Want to find out more, book a demo or simply exchange ideas? We look forward to hearing from you!
We use cookies to optimize our website and our service.
Functional
Always active
Technical storage or access is strictly necessary for the lawful purpose of enabling the use of a particular service expressly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a message over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that have not been requested by the subscriber or user.
Statistics
The technical storage or access, which is carried out exclusively for statistical purposes.Technical storage or access used solely for anonymous statistical purposes. Without a subpoena, the voluntary consent of your Internet service provider, or additional records from third parties, information stored or accessed for this purpose alone generally cannot be used to identify you.
Marketing
Technical storage or access is necessary to create user profiles, to send advertisements, or to track the user on a website or across multiple websites for similar marketing purposes.