cve-2026-58231

CRITICAL CVSS 10.0 opencve
Description

SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation. Successful exploitation could enable arbitrary code execution and compromise internal components, resulting in high impact on confidentiality, integrity, and availability of the application.

Timeline
Published
2026-08-11 11:17 UTC
Last Modified
2026-08-17
CVSS Details

CVSS details not available.

Affected Products

No product information available.

Weaknesses (CWE)
CVSS metrics
Version Base Severity Vector Exploitability Impact Source
3.1 10.0 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H mitre
3.1 10.0 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H nvd
3.1 10.0 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H opencve
References

No references available.

Linked Vulnerabilities

No linked vulnerabilities found.

{
  "cve": "CVE-2026-58231",
  "enrichment": {
    "affected": [
      {
        "configurations": [
          {
            "platform": null,
            "status": "affected",
            "versions": {
              "scheme": "generic",
              "value": "COM_CLOUD 2211"
            }
          },
          {
            "platform": null,
            "status": "affected",
            "versions": {
              "scheme": "generic",
              "value": "2211-JDK21"
            }
          }
        ],
        "enrichment": {
          "confidence": 100.0,
          "confidence_source": "manual",
          "scores": [
            {
              "score": 100.0,
              "source": "manual"
            }
          ]
        },
        "original": {
          "product": "SAP Commerce Cloud (Data Hub Adapter)",
          "source": "cna",
          "vendor": "SAP_SE"
        },
        "product": "sap_commerce_cloud_data_hub_adapter",
        "vendor": "sap_se"
      }
    ],
    "created": "2026-08-11T12:00:05.443212+00:00",
    "updated": "2026-08-11T14:19:37.609555+00:00",
    "vendors": [
      "sap_se",
      "sap_se$PRODUCT$sap_commerce_cloud_data_hub_adapter"
    ]
  },
  "epss": {
    "score": 0.00855
  },
  "mitre": {
    "cpes": [
      "cpe:2.3:a:sap_se:sap_commerce_cloud_data_hub_adapter_:2211-jdk21:*:*:*:*:*:*:*",
      "cpe:2.3:a:sap_se:sap_commerce_cloud_data_hub_adapter_:com_cloud_2211:*:*:*:*:*:*:*"
    ],
    "created": "2026-08-11T10:21:29.039000+00:00",
    "description": "SAP Commerce Cloud allows an unauthenticated\nattacker to abuse a default authentication client and submit specially crafted\ninput to certain functions lacking sufficient validation. Successful\nexploitation could enable arbitrary code execution and compromise internal\ncomponents, resulting in high impact on confidentiality, integrity, and\navailability of the application.",
    "metrics": {
      "cvssV2_0": {},
      "cvssV3_0": {},
      "cvssV3_1": {
        "score": 10,
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
      },
      "cvssV4_0": {}
    },
    "mitre_repo_path": "cves/2026/58xxx/CVE-2026-58231.json",
    "references": [
      "https://me.sap.com/notes/3771065",
      "https://url.sap/sapsecuritypatchday"
    ],
    "title": "Improper Authorization in SAP Commerce Cloud (Data Hub Adapter)",
    "updated": "2026-08-12T03:59:57.112000+00:00",
    "vendors": [
      "sap_se",
      "sap_se$PRODUCT$sap_commerce_cloud_data_hub_adapter_"
    ],
    "weaknesses": [
      "CWE-94"
    ]
  },
  "nvd": {
    "cpes": [],
    "created": "2026-08-11T11:17:15.390000+00:00",
    "description": "SAP Commerce Cloud allows an unauthenticated\nattacker to abuse a default authentication client and submit specially crafted\ninput to certain functions lacking sufficient validation. Successful\nexploitation could enable arbitrary code execution and compromise internal\ncomponents, resulting in high impact on confidentiality, integrity, and\navailability of the application.",
    "metrics": {
      "cvssV2_0": {},
      "cvssV3_0": {},
      "cvssV3_1": {
        "score": 10.0,
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
      },
      "cvssV4_0": {}
    },
    "nvd_repo_path": "2026/CVE-2026-58231.json",
    "references": [
      "https://me.sap.com/notes/3771065",
      "https://url.sap/sapsecuritypatchday"
    ],
    "title": null,
    "updated": "2026-08-17T15:39:24.573000+00:00",
    "vendors": [],
    "weaknesses": [
      "CWE-94"
    ]
  },
  "opencve": {
    "changes": [
      {
        "created": "2026-08-11T10:45:00+00:00",
        "data": [
          {
            "details": {
              "new": "SAP Commerce Cloud allows an unauthenticated\nattacker to abuse a default authentication client and submit specially crafted\ninput to certain functions lacking sufficient validation. Successful\nexploitation could enable arbitrary code execution and compromise internal\ncomponents, resulting in high impact on confidentiality, integrity, and\navailability of the application.",
              "old": null
            },
            "type": "description"
          },
          {
            "details": {
              "new": "Improper Authorization in SAP Commerce Cloud (Data Hub Adapter)",
              "old": null
            },
            "type": "title"
          },
          {
            "details": [
              "sap_se",
              "sap_se$PRODUCT$sap_commerce_cloud_data_hub_adapter_"
            ],
            "type": "first_time"
          },
          {
            "details": {
              "added": [
                "CWE-94"
              ],
              "removed": []
            },
            "type": "weaknesses"
          },
          {
            "details": {
              "added": [
                "cpe:2.3:a:sap_se:sap_commerce_cloud_data_hub_adapter_:2211-jdk21:*:*:*:*:*:*:*",
                "cpe:2.3:a:sap_se:sap_commerce_cloud_data_hub_adapter_:com_cloud_2211:*:*:*:*:*:*:*"
              ],
              "removed": []
            },
            "type": "cpes"
          },
          {
            "details": {
              "added": [
                "sap_se",
                "sap_se$PRODUCT$sap_commerce_cloud_data_hub_adapter_"
              ],
              "removed": []
            },
            "type": "vendors"
          },
          {
            "details": {
              "added": [
                "https://me.sap.com/notes/3771065",
                "https://url.sap/sapsecuritypatchday"
              ],
              "removed": []
            },
            "type": "references"
          },
          {
            "details": {
              "added": {
                "cvssV3_1": {
                  "score": 10,
                  "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
                }
              },
              "removed": {},
              "updated": {}
            },
            "type": "metrics"
          }
        ],
        "id": "ebf3f85f-1462-4dff-bca3-919e2216b1b6"
      },
      {
        "created": "2026-08-11T15:30:00+00:00",
        "data": [
          {
            "details": {
              "added": {
                "ssvc": {
                  "options": {
                    "Automatable": "yes",
                    "Exploitation": "none",
                    "Technical Impact": "total"
                  },
                  "version": "2.0.3"
                }
              },
              "removed": {},
              "updated": {}
            },
            "type": "metrics"
          }
        ],
        "id": "6546ca81-f28c-47ee-970e-3da85a5e876a"
      },
      {
        "created": "2026-08-11T15:45:00+00:00",
        "data": [
          {
            "details": [
              "sap_se$PRODUCT$sap_commerce_cloud_data_hub_adapter"
            ],
            "type": "first_time"
          },
          {
            "details": {
              "added": [
                "sap_se$PRODUCT$sap_commerce_cloud_data_hub_adapter"
              ],
              "removed": []
            },
            "type": "vendors"
          }
        ],
        "id": "1f4bb817-f928-4114-9f90-851e2f437a41"
      }
    ],
    "cpes": {
      "data": [
        "cpe:2.3:a:sap_se:sap_commerce_cloud_data_hub_adapter_:2211-jdk21:*:*:*:*:*:*:*",
        "cpe:2.3:a:sap_se:sap_commerce_cloud_data_hub_adapter_:com_cloud_2211:*:*:*:*:*:*:*"
      ],
      "providers": [
        "mitre"
      ]
    },
    "created": {
      "data": "2026-08-11T10:21:29.039000+00:00",
      "provider": "mitre"
    },
    "description": {
      "data": "SAP Commerce Cloud allows an unauthenticated\nattacker to abuse a default authentication client and submit specially crafted\ninput to certain functions lacking sufficient validation. Successful\nexploitation could enable arbitrary code execution and compromise internal\ncomponents, resulting in high impact on confidentiality, integrity, and\navailability of the application.",
      "provider": "mitre"
    },
    "metrics": {
      "cvssV2_0": {
        "data": {},
        "provider": null
      },
      "cvssV3_0": {
        "data": {},
        "provider": null
      },
      "cvssV3_1": {
        "data": {
          "score": 10,
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        },
        "provider": "mitre"
      },
      "cvssV4_0": {
        "data": {},
        "provider": null
      },
      "epss": {
        "data": {
          "score": 0.00855
        },
        "provider": "first"
      },
      "kev": {
        "data": {},
        "provider": null
      },
      "ssvc": {
        "data": {
          "options": {
            "Automatable": "yes",
            "Exploitation": "none",
            "Technical Impact": "total"
          },
          "version": "2.0.3"
        },
        "provider": "vulnrichment"
      },
      "threat_severity": {
        "data": null,
        "provider": null
      }
    },
    "references": {
      "data": [
        "https://me.sap.com/notes/3771065",
        "https://url.sap/sapsecuritypatchday"
      ],
      "providers": [
        "mitre",
        "nvd"
      ]
    },
    "title": {
      "data": "Improper Authorization in SAP Commerce Cloud (Data Hub Adapter)",
      "provider": "mitre"
    },
    "updated": {
      "data": "2026-08-11T14:26:22.280000+00:00",
      "provider": "mitre"
    },
    "vendors": {
      "data": [
        "sap_se",
        "sap_se$PRODUCT$sap_commerce_cloud_data_hub_adapter",
        "sap_se$PRODUCT$sap_commerce_cloud_data_hub_adapter_"
      ],
      "providers": [
        "mitre",
        "enrichment"
      ]
    },
    "weaknesses": {
      "data": [
        "CWE-94"
      ],
      "providers": [
        "mitre",
        "nvd"
      ]
    }
  },
  "vulnrichment": {
    "cpes": [],
    "created": "2026-08-11T10:21:29.039000+00:00",
    "description": "SAP Commerce Cloud allows an unauthenticated\nattacker to abuse a default authentication client and submit specially crafted\ninput to certain functions lacking sufficient validation. Successful\nexploitation could enable arbitrary code execution and compromise internal\ncomponents, resulting in high impact on confidentiality, integrity, and\navailability of the application.",
    "metrics": {
      "cvssV2_0": {},
      "cvssV3_0": {},
      "cvssV3_1": {},
      "cvssV4_0": {},
      "kev": {},
      "ssvc": {
        "options": {
          "Automatable": "yes",
          "Exploitation": "none",
          "Technical Impact": "total"
        },
        "version": "2.0.3"
      }
    },
    "references": [],
    "title": "Improper Authorization in SAP Commerce Cloud (Data Hub Adapter)",
    "updated": "2026-08-11T14:26:17.960000+00:00",
    "vendors": [],
    "vulnrichment_repo_path": "2026/58xxx/CVE-2026-58231.json",
    "weaknesses": []
  }
}
Enrichment data
View JSON API Download JSON