CYBERSECURITYTRACKER
TRACKING3,967 stories737 vuln stories
Permanent story citation

SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code

The story is preserved as cited. Later corrections remain visibly typed and adjacent to the original snapshot.

← newsStory 4284

As cited

Citation snapshot as of .

vulnerabilities

SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code

SAP has patched a maximum-severity vulnerability (CVE-2026-58231, CVSS 10.0) in Commerce Cloud Data Hub Adapter that stems from insufficient authorization checks and input validation. The flaw permits unauthenticated attackers to execute arbitrary code on affected systems.

Why it matters: Organizations running SAP Commerce Cloud Data Hub Adapter must apply patches immediately, as the CVSS 10.0 rating and unauthenticated attack vector pose direct risk to production environments.

Source published
First seen by Cybersecurity Tracker

Source attribution