critical2026-08-11SAP Commerce CloudCVE-2026-58231

Improper Authorization in SAP Commerce Cloud Data Hub Adapter Allows Unauthenticated RCE

SAP Commerce Cloud (Data Hub Adapter)

Our Take

CVSS 10.0 — perfect score. Unauthenticated code execution via a default authentication client means any network-accessible Commerce Cloud Data Hub is a one-step compromise. If you run Commerce Cloud with Data Hub integration, this is your only priority this month. Rotate the default credentials and patch before end of day.

Vulnerability Detail

An improper authorization vulnerability in the SAP Commerce Cloud Data Hub Adapter allows an unauthenticated attacker to abuse a default authentication client. Combined with specially crafted input, this enables arbitrary code execution on the underlying server — compromising confidentiality, integrity, and availability of the Commerce Cloud platform and any connected systems. Rated CVSS 10.0 — the maximum score.

Workaround

Disable or reconfigure the default authentication client in the Data Hub Adapter configuration until the patch is applied. Restrict inbound access to Data Hub endpoints at the network perimeter.

Patch Action

Apply SAP Note 3771065 and redeploy the updated Commerce Cloud version. Verify the Data Hub Adapter authentication configuration post-patch.

Patch Info

Priority

🔴 Patch immediately

CVSS Score

10

SAP Note

3771065

CVE

CVE-2026-58231

Published

2026-08-11

← All patches