CVE-2026-58231

10.0

SAP_SE · SAP Commerce Cloud (Data Hub Adapter)

SAP Commerce Cloud (Data Hub Adapter) is vulnerable to code injection, allowing unauthenticated attackers to execute arbitrary code by sending crafted input to certain functions.

Executive summary

An unauthenticated code injection vulnerability in the SAP Commerce Cloud Data Hub Adapter allows for complete system compromise.

Vulnerability

This is a code injection vulnerability (CWE-94) resulting from insufficient input validation in the Data Hub Adapter. It is exploitable by an unauthenticated attacker who can abuse a default authentication client to submit malicious input.

Business impact

The vulnerability allows for remote code execution, which grants an attacker full control over the affected SAP Commerce Cloud instance. Given the CVSS score of 10.0, the business impact includes total loss of data confidentiality, integrity, and availability, potentially leading to severe operational disruption.

Remediation

Immediate Action: Apply the relevant security updates provided in the SAP Security Patch Day documentation for note 3771065.

Proactive Monitoring: Review application and network logs for suspicious input patterns directed at the Data Hub Adapter functions.

Compensating Controls: Utilize a Web Application Firewall (WAF) to filter and block malicious input strings targeting the vulnerable Data Hub Adapter endpoints until the official patch is deployed.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

This is a critical security flaw that requires immediate attention from SAP administrators. Organizations must verify their versioning and apply the necessary security patches identified by SAP to prevent unauthorized access and potential system-wide compromise.

More SAP_SE CVEs