Skip to content
CVSS 10.0CVSS 10.0 · CRITICAL

CVE-2026-58231RCE sin autenticación en SAP Commerce Cloud

SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation. Successful exploitation could enable arbitrary code execution and compromise internal components, resulting in high impact on confidentiality, integrity, and availability of the application.

Ver en NVD

Análisis

SAP Commerce Cloud permite a atacantes no autenticados ejecutar código arbitrario mediante el abuso de un cliente de autenticación por defecto y entradas maliciosas. Este fallo de inyección de código puede comprometer totalmente los componentes internos y la integridad de la plataforma. Es crucial actualizar las instancias afectadas para prevenir el control remoto total del sistema.

Roles relevantes

BackendJavaCloudCyberSecurityKubernetesDocker

Severidad

Puntaje: 10.0(CRITICAL)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
AV: NETWORK
AC: LOW
PR: NONE
UI: NONE
S: CHANGED
C: HIGH
I: HIGH
A: HIGH
Tipo de falla (CWE): CWE-94

EPSS

Sin puntaje EPSS aún (CVE muy reciente).

Descripción técnica

SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation. Successful exploitation could enable arbitrary code execution and compromise internal components, resulting in high impact on confidentiality, integrity, and availability of the application.

Publicada: 11/8/2026, 11:17:15
Última modificación: 11/8/2026, 15:17:31

Referencias

InicioEventosBlogRecursosCursosEquipo