CVE Tools
Back to feed
Patch released SAP Commerce Cloud rce Manufacturing Integration and Intelligence SAP auth-bypass

SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code

The Hacker News·By The Hacker News··2 min read
CVE Tools coverage

SAP has distributed a patch for a critical vulnerability in its Commerce Cloud (Data Hub Adapter) that permits unauthenticated attackers to execute arbitrary code. Identified as CVE-2026-58231">CVE-2026-58231, the flaw carries a perfect CVSS score of 10.0 due to insufficient authorization checks and input validation, which can lead to full compromise of application confidentiality, integrity, and availability.

The update also resolves three other severe issues, including CVE-2026-44772">CVE-2026-44772 and CVE-2026-44758">CVE-2026-44758 in Manufacturing Integration and Intelligence, and CVE-2026-34265">CVE-2026-34265 in Application Server ABAP for SAP NetWeaver. Security firm Onapsis advises organizations to apply the latest release immediately or configure IP Filter Sets to restrict access to vulnerable endpoints until updates are deployed.