SAP Commerce Cloud: CVSS 10 Flaw Enables Full Takeover

Step by step
How the attack could unfold (potential chain)
Click a phase for details – or let the animation play through.
PHASE 1/5 · Reconnaissance

The attacker scans the internet for exposed SAP Commerce Cloud instances with a reachable Data Hub Adapter.

T1595 – Active Scanning T1592 – Gather Victim Host Information
  • Affected release lines: COM_CLOUD 2211 and 2211-JDK21
  • Attack vector AV:N – reachable over the network, no local access
  • Low attack complexity (AC:L), easy to automate
PHASE 2/5 · Initial Access

An unauthenticated attacker abuses a default authentication client of the Data Hub Adapter.

T1190 – Exploit Public-Facing Application
  • CVE-2026-58231, CVSS 10.0 (maximum score)
  • PR:N – no privileges required, UI:N – no user interaction
  • SAP Security Note 3771065, published 2026-08-11
  • Abuse of a default authentication client per SAP CVE record
PHASE 3/5 · Execution

Specially crafted input to insufficiently validated functions leads to arbitrary code execution.

T1059 – Command and Scripting Interpreter
  • Code Injection (CWE-94) – injection and execution of foreign code
  • Functions lacking sufficient validation are exploited
  • Result: full control over the instance
PHASE 4/5 · Lateral Movement

The scope change allows impact beyond the vulnerable component onto internal components.

  • CVSS vector S:C (Scope Changed)
  • Internal components can also be compromised
  • Data Hub Adapter connects Commerce Cloud with SAP Data Hub
PHASE 5/5 · Impact

Confidentiality, integrity and availability are fully at risk – up to service outage.

T1565 – Data Manipulation T1657 – Financial Theft
  • C:H / I:H / A:H – high impact on all three security objectives
  • Data exfiltration, data manipulation and service outage possible
  • As of 2026-08-12: no confirmed active exploitation, no PoC, no CISA-KEV entry
  • Comparable case CVE-2025-31324 (SAP NetWeaver) was actively exploited within weeks
Short & clear answers
Frequently asked questions about this incident
Am I affected by the SAP vulnerability CVE-2026-58231?
Only SAP Commerce Cloud instances on the release lines COM_CLOUD 2211 and 2211-JDK21 in the context of the Data Hub Adapter are affected. A regular company website without SAP Commerce Cloud has nothing to do with this vulnerability. Check with your SAP Commerce owner or managed service provider whether an SAP Commerce Cloud instance is being operated at all.
How dangerous is this vulnerability really?
SAP rated the vulnerability at the maximum severity of CVSS 10.0. An unauthenticated attacker can execute arbitrary code over the network without a password and without user interaction, gaining full control over the instance. This combination is easy to automate and makes the flaw especially attractive to attackers.
What exactly do I need to do now?
Retrieve SAP Security Note 3771065 via your authorized SAP support access, apply the fixed release levels stated there, then rebuild the updated SAP Commerce Cloud version and re-deploy it. As a temporary measure you can restrict access to the vulnerable endpoint using an IP Filter Set—but this does not replace the patch. Document the actually running release level as verifiable proof.
Is the vulnerability already being actively exploited?
As of 12 August 2026, the reviewed public sources show no confirmed evidence of active exploitation; there is no public proof of concept and no entry in the CISA KEV catalog. This is explicitly not an all-clear, as the comparable SAP case CVE-2025-31324 was picked up by attackers very quickly. Every affected instance should be treated as an urgent patch case.
Can I test myself whether my instance is vulnerable?
No, do not attempt to verify the vulnerability via public test requests—the exact endpoint and a safe test specification are not publicly documented. Instead, compare your release and build information against SAP Security Note 3771065 through your authorized SAP support access. When in doubt, involve your authorized SAP or implementation partner.
More security news
You might also be interested in
Critical Elementor Pro Flaw: Attackers Can Fully Take Over WordPress Sites
A file upload bug in Elementor Pro up to 4.2.1 allows RCE without login. Version 4.2.2 fixes the flaw – update now!
Pods Plugin: Critical Flaw Enables Admin Takeover, No Login
A critical flaw in the WordPress plugin Pods lets attackers overwrite admin passwords without login. Over 100,000 sites are affected.
miniOrange SAML SSO: Critical Bypass Turns Attackers Into Admins
Two critical auth bypasses in the miniOrange SAML SSO plugin allow forged SAML assertions—up to full WordPress admin access.