CVE-2026-58231 โ SAP Commerce Cloud Pre-Auth RCE
Summary
CVE-2026-58231 is a maximum-severity (CVSS 10.0) unauthenticated arbitrary-code-execution vulnerability in SAP Commerce Cloud. An attacker abuses a default authentication client to submit specially crafted input to functions lacking sufficient validation, enabling arbitrary code execution without authentication.
Key Details
- Vendor: SAP Commerce Cloud
- CVSS: 10.0 (critical)
- Type: Unauthenticated remote code execution (pre-auth RCE)
- Vector: Abuse of a default authentication client + missing input validation
- Exploitation: Attempts documented beginning ~3 days after SAP shipped its fix, per Onapsis vendor analysis and Defused Cyber honeypot telemetry
- Public PoC: None published
- Fix: Patch to fixed Commerce Cloud release levels and re-deploy; IP-Filter restrictions on the vulnerable endpoint as a temporary workaround
Timeline
- 2026-08: SAP ships patch
- ~3 days post-patch: Exploitation attempts observed in the wild (Onapsis / Defused Cyber)
- 2026-08-16: Covered in daily digest
Context
Prior SAP flaws (notably Cve 2025 31324 Sap Netweaver in NetWeaver) have been weaponised by both China-nexus espionage clusters (UNC5221, UNC5174) and cybercrime groups (BianLian, RansomExx). The rapid patch-to-exploitation conveyor mirrors the week's broader pattern โ the macOS screen-sharing zero-day, SharePoint authentication bypass and Metabase SQLi all moved from advisory to active targeting within days.
Australian Relevance
A maximum-severity pre-auth RCE on an internet-facing commerce platform is exactly the class of vulnerability ACSC's Essential Eight targeting and patch-promptness guidance and the ASD Information Security Manual require local firms to remediate immediately. Treat public Cloud/Commerce deployments as high-priority attack surfaces.
Related
- Cve 2025 31324 Sap Netweaver โ Prior SAP NetWeaver flaw weaponised by espionage and cybercrime groups
- Critical Sap Commerce Cloud Vulnerability Targeted In Active Exploitation Attemp โ The incident entry for this campaign