CVE-2026-58231
SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation. Successful exploitation could enable arbitrary code execution and compromise internal components, resulting in high impact on confidentiality, integrity, and availability of the application.
- Affected products
- Sap Commerce Cloud
- CVSS 3.1
- 10.0 CRITICAL
- EPSS
- 0.7% (51th percentile)
- Weakness
- CWE-94
- NVD status
- Received
- Published
- 2026-08-11
CVE-2026-58231 at NVD
2 known exploits for CVE-2026-58231
Proof-of-concept code and exploit modules indexed by Sploitus