Skip to content

SAP Commerce Cloud: Critical Vulnerability CVE-2026-58231 Already Actively Exploited Days After Patch

In brief: CVE-2026-58231 in SAP Commerce Cloud (CVSS 10.0) enables unauthenticated access via a default authentication client and is already being actively exploited shortly after the patch was released.

A vulnerability with the maximum CVSS score of 10.0 has been registered for SAP Commerce Cloud and is already being actively exploited shortly after the patch was published. The cause is insufficient authorization checking combined with inadequate input validation.

The vulnerability CVE-2026-58231 in SAP Commerce Cloud has been rated with the highest possible CVSS score of 10.0. According to the description, the cause is insufficient authorization checking combined with inadequate input validation. Specifically, the flaw allows an unauthenticated attacker to abuse a default authentication client in order to submit requests without needing to authenticate beforehand.

What is relevant for CISOs is that exploitation attempts were already observed just a few days after the patch was published. This significantly shortens the usual window between patch release and active exploitation and increases the pressure to identify and secure affected SAP Commerce Cloud instances immediately. Since this is an unauthenticated attack vector with maximum severity, a high risk of compromise, data exfiltration, or takeover of affected systems must be assumed, particularly for instances reachable from the internet.

Operators of SAP Commerce Cloud should apply the available patch as a priority and check whether the affected default authentication client is active in their own environment and whether it can be disabled. In addition, it is advisable to review access and log data for indications of exploitation attempts that may have already occurred since the vulnerability became known.


Source: thehackernews.com · Published August 15, 2026
Lumi AI News — AI-assisted curation in accordance with Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.

Share on: