CVE-2026-58231RCE sin autenticación en SAP Commerce Cloud
SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation. Successful exploitation could enable arbitrary code execution and compromise internal components, resulting in high impact on confidentiality, integrity, and availability of the application.
Ver en NVDAnálisis
SAP Commerce Cloud permite a atacantes no autenticados ejecutar código arbitrario mediante el abuso de un cliente de autenticación por defecto y entradas maliciosas. Este fallo de inyección de código puede comprometer totalmente los componentes internos y la integridad de la plataforma. Es crucial actualizar las instancias afectadas para prevenir el control remoto total del sistema.
Roles relevantes
Severidad
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HCWE-94EPSS
Sin puntaje EPSS aún (CVE muy reciente).
Descripción técnica
SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation. Successful exploitation could enable arbitrary code execution and compromise internal components, resulting in high impact on confidentiality, integrity, and availability of the application.