← Back to browse · API

CVE-2026-58231

Severity
CRITICAL
CVSS
10.0
EPSS
0.00726
Risk score
40.25
CISA KEV
No
PoC
No
Published
2026-08-11
Modified
2026-08-12
First seen
2026-08-11
Aliases
EUVD-2026-55999, GHSA-686G-Q5W6-7J38
Products
SAP_SE:SAP Commerce Cloud (Data Hub Adapter) 2211-JDK21, SAP_SE:SAP Commerce Cloud (Data Hub Adapter) COM_CLOUD 2211
Sources
euvd EUVD-2026-55999
nvd CVE-2026-58231

Description

SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation. Successful exploitation could enable arbitrary code execution and compromise internal components, resulting in high impact on confidentiality, integrity, and availability of the application.

References