SAP Commerce Cloud flaw opens unauthenticated path to code execution
India, Aug. 12 -- SAP has patched a CVSS 10.0 vulnerability in Commerce Cloud that could allow an unauthenticated attacker to execute arbitrary code. The flaw, tracked as CVE-2026-58231, affects the Data Hub Adapter and combines inadequate authorization controls with insufficient input validation.
The security issue is especially serious because exploitation does not require valid credentials. An attacker can abuse a default authentication client and send specially crafted input to affected functions, potentially turning an exposed application interface into a route for code execution.
CVE-2026-58231 can allow successful attackers to compromise internal components of the affected application. The reported impact covers confidentiality, ...
Click here to read full article from source
To read the full article or to get the complete feed from this publication, please
Contact Us.