SAPCVE-2026-58231
SAP Commerce Cloud (Data Hub Adapter): remote code execution
Critical10.0CVE-2026-58231 · Published Aug 11, 2026 · updated Aug 17, 2026
SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation. Successful exploitation could enable arbitrary code execution and compromise internal components, resulting in high impact on confidentiality, integrity, and availability of the application.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| SAP Commerce Cloud (Data Hub Adapter) Product | <= COM_CLOUD 2211 | No fix yet |
| <= 2211-JDK21 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-94
More SAP advisories
All SAP| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 11 | SAP Business AI Platform (Approuter): improper signature check | Medium5.9 | No fix yet |
| Aug 11 | SAP Business AI Platform (Approuter): path traversal | Medium5.9 | No fix yet |
| Aug 11 | SAP Approuter does not sufficiently sanitize certain request headers before... | Medium5.3 | No fix yet |
| Aug 11 | SAP NetWeaver Application Server ABAP: cross-site scripting | Medium6.3 | No fix yet |
| Aug 11 | SAP BusinessObjects Business Intelligence Platform (Central : hard-coded key | High7.9 | No fix yet |
| Aug 11 | SAP S/4 HANA (Reprocess Bank Statement Items): privilege escalation | Medium4.3 | No fix yet |