← back
CVE-2026-58231criticalobserved exploitationCWE-94

Improper Authorization in SAP Commerce Cloud (Data Hub Adapter)

70Vexday Risk Score

Prioritize patching. It exploitation observed by VulnCheck and has a public proof of concept.

ssvc Actcvss 10epss 1.7%
from disclosure to weapon4 days
Published on NVDAug 11
1st PoC+4d
VulnCheck+3d
exploitation probability
1.7%top 25% of all CVEs
observed exploitation
yesVulnCheck
2 public exploit(s)
SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation. Successful exploitation could enable arbitrary code execution and compromise internal components, resulting in high impact on confidentiality, integrity, and availability of the application.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.