CVE Tools

SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code

The Hacker NewsBy The Hacker News

PatchSAP Commerce CloudManufacturing Integration and Intelligence

Our summary

SAP has distributed a patch for a critical vulnerability in its Commerce Cloud (Data Hub Adapter) that permits unauthenticated attackers to execute arbitrary code. Identified as CVE-2026-58231">CVE-2026-58231, the flaw carries a perfect CVSS score of 10.0 due to insufficient authorization checks and input validation, which can lead to full compromise of application confidentiality, integrity, and availability.

The update also resolves three other severe issues, including CVE-2026-44772">CVE-2026-44772 and CVE-2026-44758">CVE-2026-44758 in Manufacturing Integration and Intelligence, and CVE-2026-34265">CVE-2026-34265 in Application Server ABAP for SAP NetWeaver. Security firm Onapsis advises organizations to apply the latest release immediately or configure IP Filter Sets to restrict access to vulnerable endpoints until updates are deployed.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store