SAP Commerce Cloud CVE-2026
Attackers actively exploit unauthenticated RCE CVE-2026-58231 (CVSS 10.0) in SAP Commerce Cloud days after patch release.
CVE-2026-58231, a maximum-severity flaw in SAP Commerce Cloud (CVSS 10.0), allows unauthenticated attackers to abuse a default authentication client and bypass insufficient validation, achieving arbitrary code execution and compromise of internal components. Defused Cyber researchers observed exploitation attempts against honeypots only three days after SAP released the patch. The flaw had no public PoC and was not previously known to be exploited. The attackers are unknown, though past critical SAP flaws have been exploited by China-linked groups UNC5221 and UNC5174 and ransomware gangs.
- Unauthenticated RCE via default authentication client and insufficient validation, CVSS 10.0
- Honeypots caught exploitation attempts three days after SAP's patch; no public PoC exists
- Prior critical SAP flaws were exploited by China-linked UNC5221/UNC5174 and ransomware gangs
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-58231 | SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking s SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation. Successful exploitation could enable arbitrary code execution and compromise internal components, resulting in high impact on confidentiality, integrity, and availability of the application. NVD description · AI analysis pending | 10.0 | 2% | — | — |
Full article267 words · extracted from securityaffairs.com · click to collapse

Attackers are actively exploiting a maximum severity SAP Commerce Cloud vulnerability, tracked as CVE-2026-58231, just days after SAP released a patch.
A critical SAP Commerce Cloud vulnerability, tracked as CVE-2026-58231 (CVSS score of 10.0), is under active exploitation just days after SAP released a patch. The flaw stems from insufficient authorization checks and input validation.
“SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation.” reads the advisory. “Successful exploitation could enable arbitrary code execution and compromise internal components, resulting in high impact on confidentiality, integrity, and availability of the application.”
An unauthenticated attacker can abuse a default authentication client and send crafted input to vulnerable functions, potentially achieving arbitrary code execution and compromising internal components.
Researchers at Defused Cyber observed exploitation attempts against honeypots only three days after the patch was released. The researchers pointed out that this vulnerability has no public PoC and had not been known to be exploited prior to their discovery.
— Defused (@DefusedCyber) August 14, 2026🚨 First exploitation attempts against CVE-2026-58231 (unauth RCE in SAP Commerce Cloud, CVSS 10.0) is now hitting our honeypots – 3 days after patch day.
This vulnerability has no public PoC and is not known to be exploited.
View the full payload 👉https://t.co/GXFaqggV8a pic.twitter.com/zMJuo45Ahx
The attackers behind the current exploitation remain unknown. However, previous critical SAP flaws have been exploited by China-linked APT groups, including UNC5221 and UNC5174, and ransomware gangs.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, SAP Commerce Cloud)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/197244/security/sap-commerce-cloud-cve-2026-58231-exploited-in-the-wild.html