CYBERSECURITYTRACKER
TRACKING7,811 stories in this site build1,697 vulnerability news stories in this site build
Permanent story citation

SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 4284

As cited

Copy frozen at (site build).

vulnerabilities

SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code

SAP has patched a maximum-severity vulnerability (CVE-2026-58231, CVSS 10.0) in Commerce Cloud Data Hub Adapter that stems from insufficient authorization checks and input validation. The flaw permits unauthenticated attackers to execute arbitrary code on affected systems.

Why it matters: Organizations running SAP Commerce Cloud Data Hub Adapter must apply patches immediately, as the CVSS 10.0 rating and unauthenticated attack vector pose direct risk to production environments.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code

SAP has patched a maximum-severity vulnerability (CVE-2026-58231, CVSS 10.0) in Commerce Cloud Data Hub Adapter that stems from insufficient authorization checks and input validation. The flaw permits unauthenticated attackers to execute arbitrary code on affected systems.

Why it matters: Organizations running SAP Commerce Cloud Data Hub Adapter must apply patches immediately, as the CVSS 10.0 rating and unauthenticated attack vector pose direct risk to production environments.

VendorsSAPAdobe
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary