SAP Commerce Cloud Data Hub Adapter Unauthenticated RCE
Insufficient authorization checks and input validation in SAP Commerce Cloud Data Hub Adapter allow unauthenticated remote code execution. CVSS 10.0.
- Vendor
- SAP
- Product
- Commerce Cloud (Data Hub Adapter)
- CVSS
- 10.0
- EPSS (exploit probability)
- N/A
- Status
- patched
- Published
CVE-2026-58231 is a maximum-severity vulnerability in SAP Commerce Cloud’s Data Hub Adapter component. Two weaknesses combine: insufficient authorization checks on inbound requests, and insufficient input validation on the data those requests carry. Together, they allow an unauthenticated attacker to reach the vulnerable endpoint and execute arbitrary code on the underlying system.
SAP released a patch on August 12, 2026. Sources: NVD — CVE-2026-58231, The Hacker News.
Affected component: SAP Commerce Cloud, Data Hub Adapter. Specific affected version ranges: consult SAP Security Notes via the SAP Support Portal.
Action: Apply SAP’s patch immediately. If patching is not immediately possible, restrict network access to the Data Hub Adapter from untrusted segments and review endpoint logs.
See full coverage: SAP Commerce Cloud CVSS 10 RCE — Patch Released.
