CVE-2026-58231Unauthenticated RCE in SAP Commerce Cloud
SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation. Successful exploitation could enable arbitrary code execution and compromise internal components, resulting in high impact on confidentiality, integrity, and availability of the application.
View on NVDAnalysis
SAP Commerce Cloud permite a atacantes no autenticados ejecutar código arbitrario mediante el abuso de un cliente de autenticación por defecto y entradas maliciosas. Este fallo de inyección de código puede comprometer totalmente los componentes internos y la integridad de la plataforma. Es crucial actualizar las instancias afectadas para prevenir el control remoto total del sistema.
Relevant roles
Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HCWE-94EPSS
No EPSS score yet (CVE may be too fresh).
Technical description
SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation. Successful exploitation could enable arbitrary code execution and compromise internal components, resulting in high impact on confidentiality, integrity, and availability of the application.