Description
SAP Commerce Cloud allows an unauthenticated
attacker to abuse a default authentication client and submit specially crafted
input to certain functions lacking sufficient validation. Successful
exploitation could enable arbitrary code execution and compromise internal
components, resulting in high impact on confidentiality, integrity, and
availability of the application.
Published: 2026-08-11
Score: 10 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 11 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Sap Se sap Commerce Cloud Data Hub Adapter
Vendors & Products Sap Se sap Commerce Cloud Data Hub Adapter

Tue, 11 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 10:45:00 +0000

Type Values Removed Values Added
Description SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation. Successful exploitation could enable arbitrary code execution and compromise internal components, resulting in high impact on confidentiality, integrity, and availability of the application.
Title Improper Authorization in SAP Commerce Cloud (Data Hub Adapter)
First Time appeared Sap Se
Sap Se sap Commerce Cloud Data Hub Adapter
Weaknesses CWE-94
CPEs cpe:2.3:a:sap_se:sap_commerce_cloud_data_hub_adapter_:2211-jdk21:*:*:*:*:*:*:*
cpe:2.3:a:sap_se:sap_commerce_cloud_data_hub_adapter_:com_cloud_2211:*:*:*:*:*:*:*
Vendors & Products Sap Se
Sap Se sap Commerce Cloud Data Hub Adapter
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Sap Se Sap Commerce Cloud Data Hub Adapter
cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published:

Updated: 2026-08-11T14:26:22.280Z

Reserved: 2026-06-29T19:34:28.222Z

Link: CVE-2026-58231

cve-icon Vulnrichment

Updated: 2026-08-11T14:26:17.960Z

cve-icon NVD

Status : Received

Published: 2026-08-11T11:17:15.390

Modified: 2026-08-11T15:17:31.280

Link: CVE-2026-58231

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-11T14:19:37Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')