SAP has released patches for a maximum-severity vulnerability in Commerce Cloud (Data Hub Adapter) that could allow unauthenticated attackers to execute arbitrary code. The flaw, tracked as CVE-2026-58231, carries a CVSS score of 10.0 and stems from insufficient authorization checks and input validation. According to the description on CVE.org, an attacker can abuse a default authentication client and submit specially crafted input to functions lacking proper validation, leading to arbitrary code execution and compromise of internal components, with high impact on confidentiality, integrity, and availability.
Security firm Onapsis urges customers to apply the fixed Commerce Cloud release and re-deploy the updated version. As a temporary workaround, configuring an IP Filter Set can restrict access to the vulnerable endpoint until the patch is applied.
In addition, SAP’s August 2026 security update addresses three other critical vulnerabilities:
- CVE-2026-44772 (CVSS 9.9): A code injection vulnerability in Manufacturing Integration and Intelligence that allows a low-privileged attacker to submit crafted input, causing the application to fetch and process attacker-controlled content from an external source, leading to arbitrary command execution. After patching, customers must maintain the new system property ‘Secure Transformer’ with a list of allowed hosts for XSL files.
- CVE-2026-34265 (CVSS 9.8): An out-of-bounds write vulnerability in Application Server ABAP for SAP NetWeaver and ABAP Platform. An unauthenticated attacker can exploit logical errors in DIAG protocol parsing, resulting in memory corruption, disclosure of sensitive system information, or system crashes.
- CVE-2026-44758 (CVSS 9.1): A code injection vulnerability in Manufacturing Integration and Intelligence that allows an attacker with high privileges to execute arbitrary commands on the underlying OS. Onapsis notes it involves a servlet component susceptible to server-side template injection (SSTI) and server-side request forgery (SSRF), which could lead to command execution. The patch removes the vulnerable servlet.
Organizations using affected SAP products should prioritize applying the latest patches and implementing recommended mitigations to protect against potential exploitation.
CVEs: CVE-2026-58231, CVE-2026-44772, CVE-2026-34265, CVE-2026-44758
Products: SAP Commerce Cloud, SAP Manufacturing Integration and Intelligence, SAP Application Server ABAP, SAP NetWeaver, ABAP Platform
Original source: thehackernews.com