Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

SAP Commerce Cloud Flaw Leaves Unauthenticated Attackers Vulnerable to Arbitrary Code Execution



A recent security flaw discovered in SAP Commerce Cloud has left unauthenticated attackers with the potential to execute arbitrary code. The patch released by SAP aims to address this vulnerability, but the question remains as to what other risks and consequences this flaw may pose.

  • An arbitrary code execution vulnerability has been discovered in SAP Commerce Cloud (Data Hub Adapter) with a CVE identifier of CVE-2026-58231.
  • The vulnerability is rated 10.0 on the CVSS scoring system and can be exploited by an unauthenticated attacker to execute malicious code.
  • SAP has released patches to address this issue, recommending customers patch to a fixed Commerce Cloud release and re-deploy the updated version.
  • Additional critical flaws have been addressed in the August 2026 update, including code injection vulnerabilities in Manufacturing Integration and Intelligence.
  • The patched release removes the vulnerable servlet component, preventing server-side template injection and SSRF attacks.



  • SAP has recently released patches to address a maximum-severity security flaw impacting Commerce Cloud (Data Hub Adapter) that could result in arbitrary code execution. This vulnerability, assigned the CVE identifier CVE-2026-58231, is rated 10.0 on the CVSS scoring system. It has been described as a case of insufficient authorization checks and input validation.

    The problem arises from the fact that SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation. This means that any individual with access to the vulnerable endpoint can exploit this flaw, potentially leading to arbitrary code execution and compromise internal components. As a result, there is a high impact on confidentiality, integrity, and availability of the application.

    SAP security company Onapsis has urged customers to patch to a fixed Commerce Cloud release and then re-deploy the updated SAP Commerce Cloud version. In addition, a temporary workaround can be implemented by configuring an IP Filter Set to restrict access to the vulnerable endpoint.

    Furthermore, SAP has also addressed three other critical flaws as part of its August 2026 update - CVE-2026-44772 (CVSS score: 9.9) - A code injection vulnerability in Manufacturing Integration and Intelligence; CVE-2026-34265 (CVSS score: 9.8) - An out-of-bounds write vulnerability in Application Server ABAP for SAP NetWeaver and ABAP Platform that allows an unauthenticated attacker to exploit logical errors in DIAG protocol parsing, resulting in memory corruption. This could be exploited to disclose sensitive system information or crash the system; CVE-2026-44758 (CVSS score: 9.1) - A code injection vulnerability in Manufacturing Integration and Intelligence that could allow an attacker with high privileges to execute arbitrary commands on the underlying operating system.

    The patch released by SAP removes the vulnerable servlet component, which was susceptible to server-side template injection (SSTI) and server-side request forgery (SSRF), paving the way for command execution.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/SAP-Commerce-Cloud-Flaw-Leaves-Unauthenticated-Attackers-Vulnerable-to-Arbitrary-Code-Execution-ehn.shtml

  • https://thehackernews.com/2026/08/sap-commerce-cloud-flaw-could-let.html

  • https://nvd.nist.gov/vuln/detail/CVE-2026-58231

  • https://www.cvedetails.com/cve/CVE-2026-58231/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-44772

  • https://www.cvedetails.com/cve/CVE-2026-44772/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-34265

  • https://www.cvedetails.com/cve/CVE-2026-34265/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-44758

  • https://www.cvedetails.com/cve/CVE-2026-44758/


  • Published: Wed Aug 12 03:18:42 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us