SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code
SAP patched a CVSS 10.0 unauthenticated RCE flaw (CVE-2026-58231) in Commerce Cloud's Data Hub Adapter, plus three critical flaws in NetWeaver and Manufacturing.
SAP's August 2026 updates fix CVE-2026-58231, a CVSS 10.0 flaw in Commerce Cloud's Data Hub Adapter where insufficient authorization checks and input validation let unauthenticated attackers execute arbitrary code. Onapsis urged customers to patch and redeploy, with an IP Filter Set on the vulnerable endpoint offered as a temporary workaround. The update also fixed CVE-2026-44772 (CVSS 9.9) and CVE-2026-44758 (CVSS 9.1), code injection flaws in Manufacturing Integration and Intelligence involving SSRF and SSTI, and CVE-2026-34265 (CVSS 9.8), an out-of-bounds write in NetWeaver ABAP's DIAG protocol parsing that can leak information or crash systems.