{"cve":"CVE-2026-58231","enrichment":{"affected":[{"configurations":[{"platform":null,"status":"affected","versions":{"scheme":"generic","value":"COM_CLOUD 2211"}},{"platform":null,"status":"affected","versions":{"scheme":"generic","value":"2211-JDK21"}}],"enrichment":{"confidence":100.0,"confidence_source":"manual","scores":[{"score":100.0,"source":"manual"}]},"original":{"product":"SAP Commerce Cloud (Data Hub Adapter)","source":"cna","vendor":"SAP_SE"},"product":"sap_commerce_cloud_data_hub_adapter","vendor":"sap_se"}],"created":"2026-08-11T12:00:05.443212+00:00","updated":"2026-08-11T14:19:37.609555+00:00","vendors":["sap_se","sap_se$PRODUCT$sap_commerce_cloud_data_hub_adapter"]},"epss":{"score":0.00855},"mitre":{"cpes":["cpe:2.3:a:sap_se:sap_commerce_cloud_data_hub_adapter_:2211-jdk21:*:*:*:*:*:*:*","cpe:2.3:a:sap_se:sap_commerce_cloud_data_hub_adapter_:com_cloud_2211:*:*:*:*:*:*:*"],"created":"2026-08-11T10:21:29.039000+00:00","description":"SAP Commerce Cloud allows an unauthenticated\nattacker to abuse a default authentication client and submit specially crafted\ninput to certain functions lacking sufficient validation. Successful\nexploitation could enable arbitrary code execution and compromise internal\ncomponents, resulting in high impact on confidentiality, integrity, and\navailability of the application.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{"score":10,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"},"cvssV4_0":{}},"mitre_repo_path":"cves/2026/58xxx/CVE-2026-58231.json","references":["https://me.sap.com/notes/3771065","https://url.sap/sapsecuritypatchday"],"title":"Improper Authorization in SAP Commerce Cloud (Data Hub Adapter)","updated":"2026-08-12T03:59:57.112000+00:00","vendors":["sap_se","sap_se$PRODUCT$sap_commerce_cloud_data_hub_adapter_"],"weaknesses":["CWE-94"]},"nvd":{"cpes":[],"created":"2026-08-11T11:17:15.390000+00:00","description":"SAP Commerce Cloud allows an unauthenticated\nattacker to abuse a default authentication client and submit specially crafted\ninput to certain functions lacking sufficient validation. Successful\nexploitation could enable arbitrary code execution and compromise internal\ncomponents, resulting in high impact on confidentiality, integrity, and\navailability of the application.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{"score":10.0,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"},"cvssV4_0":{}},"nvd_repo_path":"2026/CVE-2026-58231.json","references":["https://me.sap.com/notes/3771065","https://url.sap/sapsecuritypatchday"],"title":null,"updated":"2026-08-17T15:39:24.573000+00:00","vendors":[],"weaknesses":["CWE-94"]},"opencve":{"changes":[{"created":"2026-08-11T10:45:00+00:00","data":[{"details":{"new":"SAP Commerce Cloud allows an unauthenticated\nattacker to abuse a default authentication client and submit specially crafted\ninput to certain functions lacking sufficient validation. Successful\nexploitation could enable arbitrary code execution and compromise internal\ncomponents, resulting in high impact on confidentiality, integrity, and\navailability of the application.","old":null},"type":"description"},{"details":{"new":"Improper Authorization in SAP Commerce Cloud (Data Hub Adapter)","old":null},"type":"title"},{"details":["sap_se","sap_se$PRODUCT$sap_commerce_cloud_data_hub_adapter_"],"type":"first_time"},{"details":{"added":["CWE-94"],"removed":[]},"type":"weaknesses"},{"details":{"added":["cpe:2.3:a:sap_se:sap_commerce_cloud_data_hub_adapter_:2211-jdk21:*:*:*:*:*:*:*","cpe:2.3:a:sap_se:sap_commerce_cloud_data_hub_adapter_:com_cloud_2211:*:*:*:*:*:*:*"],"removed":[]},"type":"cpes"},{"details":{"added":["sap_se","sap_se$PRODUCT$sap_commerce_cloud_data_hub_adapter_"],"removed":[]},"type":"vendors"},{"details":{"added":["https://me.sap.com/notes/3771065","https://url.sap/sapsecuritypatchday"],"removed":[]},"type":"references"},{"details":{"added":{"cvssV3_1":{"score":10,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"ebf3f85f-1462-4dff-bca3-919e2216b1b6"},{"created":"2026-08-11T15:30:00+00:00","data":[{"details":{"added":{"ssvc":{"options":{"Automatable":"yes","Exploitation":"none","Technical Impact":"total"},"version":"2.0.3"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"6546ca81-f28c-47ee-970e-3da85a5e876a"},{"created":"2026-08-11T15:45:00+00:00","data":[{"details":["sap_se$PRODUCT$sap_commerce_cloud_data_hub_adapter"],"type":"first_time"},{"details":{"added":["sap_se$PRODUCT$sap_commerce_cloud_data_hub_adapter"],"removed":[]},"type":"vendors"}],"id":"1f4bb817-f928-4114-9f90-851e2f437a41"}],"cpes":{"data":["cpe:2.3:a:sap_se:sap_commerce_cloud_data_hub_adapter_:2211-jdk21:*:*:*:*:*:*:*","cpe:2.3:a:sap_se:sap_commerce_cloud_data_hub_adapter_:com_cloud_2211:*:*:*:*:*:*:*"],"providers":["mitre"]},"created":{"data":"2026-08-11T10:21:29.039000+00:00","provider":"mitre"},"description":{"data":"SAP Commerce Cloud allows an unauthenticated\nattacker to abuse a default authentication client and submit specially crafted\ninput to certain functions lacking sufficient validation. Successful\nexploitation could enable arbitrary code execution and compromise internal\ncomponents, resulting in high impact on confidentiality, integrity, and\navailability of the application.","provider":"mitre"},"metrics":{"cvssV2_0":{"data":{},"provider":null},"cvssV3_0":{"data":{},"provider":null},"cvssV3_1":{"data":{"score":10,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"},"provider":"mitre"},"cvssV4_0":{"data":{},"provider":null},"epss":{"data":{"score":0.00855},"provider":"first"},"kev":{"data":{},"provider":null},"ssvc":{"data":{"options":{"Automatable":"yes","Exploitation":"none","Technical Impact":"total"},"version":"2.0.3"},"provider":"vulnrichment"},"threat_severity":{"data":null,"provider":null}},"references":{"data":["https://me.sap.com/notes/3771065","https://url.sap/sapsecuritypatchday"],"providers":["mitre","nvd"]},"title":{"data":"Improper Authorization in SAP Commerce Cloud (Data Hub Adapter)","provider":"mitre"},"updated":{"data":"2026-08-11T14:26:22.280000+00:00","provider":"mitre"},"vendors":{"data":["sap_se","sap_se$PRODUCT$sap_commerce_cloud_data_hub_adapter","sap_se$PRODUCT$sap_commerce_cloud_data_hub_adapter_"],"providers":["mitre","enrichment"]},"weaknesses":{"data":["CWE-94"],"providers":["mitre","nvd"]}},"vulnrichment":{"cpes":[],"created":"2026-08-11T10:21:29.039000+00:00","description":"SAP Commerce Cloud allows an unauthenticated\nattacker to abuse a default authentication client and submit specially crafted\ninput to certain functions lacking sufficient validation. Successful\nexploitation could enable arbitrary code execution and compromise internal\ncomponents, resulting in high impact on confidentiality, integrity, and\navailability of the application.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{},"cvssV4_0":{},"kev":{},"ssvc":{"options":{"Automatable":"yes","Exploitation":"none","Technical Impact":"total"},"version":"2.0.3"}},"references":[],"title":"Improper Authorization in SAP Commerce Cloud (Data Hub Adapter)","updated":"2026-08-11T14:26:17.960000+00:00","vendors":[],"vulnrichment_repo_path":"2026/58xxx/CVE-2026-58231.json","weaknesses":[]}}