CVE-2026-58231: SAP SE SAP Commerce Cloud Data Hub Adapter
Critical severity, CVSS 10.0. EPSS: 0.9% chance of exploitation in the next 30 days.
SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation. Successful exploitation could enable arbitrary code execution and compromise internal components, resulting in high impact on confidentiality, integrity, and availability of the application.
Affected products
- SAP SE SAP Commerce Cloud Data Hub Adapter: version 2211-JDK21 only
Published 2026-08-11. Last modified 2026-08-17.