CVE-2026-58231 PUBLISHED

Improper Authorization in SAP Commerce Cloud (Data Hub Adapter)

Assigner: sap
Reserved: 29.06.2026 Published: 11.08.2026 Updated: 12.08.2026

SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation. Successful exploitation could enable arbitrary code execution and compromise internal components, resulting in high impact on confidentiality, integrity, and availability of the application.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVSS Score: 10

Product Status

Vendor SAP_SE
Product SAP Commerce Cloud (Data Hub Adapter)
Versions Default: unaffected
  • Version COM_CLOUD 2211 is affected
  • Version 2211-JDK21 is affected

References

Problem Types

  • CWE-94: Improper Control of Generation of Code CWE