CVE-2026-58231: exploitation status and patch state

CVE-2026-58231 · CVSS 10.0 CRITICAL

SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation. Successful exploitation could enable arbitrary code execution and compromise internal components, resulting in high impact on confidentiality, integrity, and availability of the application.

Is CVE-2026-58231 exploited?

Which products and versions are affected?

No affected package list recorded here yet.

Is there a patch?

No patch identifier recorded here yet.

What PlainSec published about CVE-2026-58231

Primary sources

What this record does not say

KEV and EPSS are re-checked daily. Record last updated 2026-08-15.