Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5022 articles · 188920 vulns · 37/41 feeds (7d)
← Back to list
10.0
CVE-2026-58231
sap · sap commerce cloud (data hub adapter)

Improper Authorization in SAP Commerce Cloud (Data Hub Adapter)

Description

SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation. Successful exploitation could enable arbitrary code execution and compromise internal components, resulting in high impact on confidentiality, integrity, and availability of the application.

Affected Products

VendorProductVersions
sapsap commerce cloud (data hub adapter)COM_CLOUD 2211, 2211-JDK21

References

  • https://me.sap.com/notes/3771065
  • https://url.sap/sapsecuritypatchday

Related News (6 articles)

Tier D
The Hacker News10h ago
SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code
→ No new info (linked only)
Tier D
CSO Online16h ago
Patch Tuesday August 2026: A zero-day WinSock driver hole under exploit, and a maximum severity SAP vulnerability
→ No new info (linked only)
Tier D
SecurityWeek1d ago
SAP Patches Critical Code Injection, Memory Corruption Vulnerabilities
→ No new info (linked only)
Tier D
Heise Security1d ago
Patchday: SAP Commerce Cloud komplett kompromittierbar
→ No new info (linked only)
Tier C
VulDB1d ago
CVE-2026-58231 | SAP Commerce Cloud 2211-JDK21/COM_CLOUD 2211 improper authentication
→ No new info (linked only)
Tier B
CERT-FR1d ago
Multiples vulnérabilités dans les produits SAP (11 août 2026)
→ No new info (linked only)
CVSS 3.110.0 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
CWECWE-94
PublishedAug 11, 2026
Trending Score69
Source articles6
Independent6
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-34265
Memory Corruption vulnerability in Application Server ABAP for SAP NetWeaver and ABAP Platform
Trending: 61
CRITICALCVE-2026-44758
Code Injection vulnerability in Manufacturing Integration and Intelligence
Trending: 52
HIGHCVE-2026-44764
Missing Authorization Check in SAP Manufacturing Integration and Intelligence
Trending: 46
HIGHCVE-2026-44765
Missing Authorization Check in SAP Manufacturing Integration and Intelligence
Trending: 46
MEDIUMCVE-2026-40130
Memory Corruption vulnerability in SAPSPrint Service
Trending: 43

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 11, 2026
Discovered by ZDM
Aug 11, 2026