SAP Commerce Cloud flaw CVE-2026-58231 draws exploitation attempts days after patch
This digest was compiled by AI from multiple sources — links to the originals are below.

Attempts to exploit a maximum-severity flaw in SAP Commerce Cloud began three days after the vendor released its patch, threat intelligence firm Defused Cyber reported. The vulnerability, CVE-2026-58231, carries a 10.0 CVSS rating and could allow unauthenticated attackers to execute arbitrary code and compromise internal components.
Key Facts
- CVE-2026-58231 carries a maximum 10.0 CVSS rating and stems from insufficient authorization checks and input validation.
- Defused Cyber said exploitation attempts against the flaw began hitting its honeypots three days after SAP released the patch.
- Onapsis said successful exploitation of CVE-2026-58231 could permit arbitrary code execution and compromise internal components of SAP Commerce Cloud.
- Onapsis said SAP customers must patch to the fixed Commerce Cloud release levels and re-deploy the updated version, or configure an IP Filter Set to restrict access to the vulnerable endpoint.
- No public proof-of-concept is available for CVE-2026-58231, and no group behind the exploitation attempts has been identified.
Exploitation Attempts
SAP Commerce Cloud vulnerability CVE-2026-58231 is rated 10.0 on the CVSS severity scale. The flaw involves insufficient authorization checks and input validation in certain functions, according to CVE.org. Defused Cyber recorded exploitation attempts against its honeypot systems three days after SAP released the patch. Defused Cyber also said the vulnerability had no public proof-of-concept and was not known to be exploited at the time of its X post on Friday.
SAP and Onapsis Guidance
SAP security company Onapsis said successful exploitation could allow arbitrary code execution and compromise internal components. Onapsis said customers must patch to the fixed Commerce Cloud release levels and re-build or re-deploy the updated SAP Commerce Cloud version. As a temporary workaround, customers can configure an IP Filter Set to restrict access to the vulnerable endpoint. No details are available on who is behind the exploitation efforts targeting CVE-2026-58231.
2 sources
SAP Commerce Cloud flaw CVE-2026-58231 draws exploitation attempts days after patch



