India, Aug. 12 -- SAP has patched a CVSS 10.0 vulnerability in Commerce Cloud that could allow an unauthenticated attacker to execute arbitrary code. The flaw, tracked as CVE-2026-58231, affects the Data Hub Adapter and combines inadequate authorization controls with insufficient input validation.

The security issue is especially serious because exploitation does not require valid credentials. An attacker can abuse a default authentication client and send specially crafted input to affected functions, potentially turning an exposed application interface into a route for code execution.

CVE-2026-58231 can allow successful attackers to compromise internal components of the affected application. The reported impact covers confidentiality, ...