VMTech
Discuss a project

SAP fixes CVSS 10.0 Commerce Cloud Data Hub Adapter flaw

SAP fixes CVSS 10.0 Commerce Cloud Data Hub Adapter flaw

SAP has released patches for CVE-2026-58231, a maximum-severity vulnerability affecting SAP Commerce Cloud’s Data Hub Adapter. Rated 10.0 on the CVSS scale, the flaw could allow an unauthenticated attacker to execute arbitrary code by abusing a default authentication client and submitting specially crafted input to functions with insufficient validation.

The issue is described as a combination of insufficient authorization checks and input validation. Successful exploitation could compromise internal components and have a high effect on the confidentiality, integrity and availability of the application.

Patching and temporary exposure reduction

Onapsis has advised affected customers to update to a fixed SAP Commerce Cloud release and redeploy the updated version. The redeployment step is material: installing a fix alone does not complete the remediation described for the product.

Where a fix cannot be applied immediately, SAP says exposure can be reduced by configuring an IP Filter Set that restricts access to the vulnerable endpoint. This is a temporary mitigation rather than a replacement for moving to a fixed release.

The vulnerability arrives amid a stream of enterprise attack paths involving exposed infrastructure and authentication weaknesses, including Cisco vulnerabilities, ClickFix chains and AI-agent incidents on Cisco vulnerabilities, ClickFix chains and AI-agent incidents, where defenders must rapidly distinguish urgent patching work from longer-term hardening.

Other critical SAP fixes in August

SAP’s August 2026 update also addresses three additional critical vulnerabilities. CVE-2026-44772, rated 9.9, is a code-injection flaw in Manufacturing Integration and Intelligence. It affects a servlet that can let a low-privileged attacker supply crafted input, causing the application to fetch and process attacker-controlled external content and ultimately execute arbitrary commands on the host.

After applying that patch, customers must maintain the new Secure Transformer system property with an allowlist of hosts that provide XSL files. Only XSL files hosted on those approved systems can be consumed by the affected servlet.

CVE-2026-34265, rated 9.8, is an out-of-bounds write issue in Application Server ABAP for SAP NetWeaver and ABAP Platform. An unauthenticated attacker could exploit logical errors in DIAG protocol parsing, causing memory corruption that may disclose sensitive system information or crash the system.

The remaining issue, CVE-2026-44758, has a CVSS score of 9.1 and affects Manufacturing Integration and Intelligence. Onapsis said the vulnerable servlet component was susceptible to server-side template injection and server-side request forgery, potentially enabling command execution for an attacker with high privileges. SAP’s patch removes that servlet component.

Business implication

Security and SAP operations teams should prioritise an inventory of Commerce Cloud Data Hub Adapter exposure, deploy and redeploy the fixed release, restrict the vulnerable endpoint when remediation is delayed, and validate the required allowlist configuration for the Manufacturing Integration and Intelligence update.

#sapsecurity#vulnerability#patchmanagement#commercecloud
Open analytics
On the site 2 views
min read 4 12.08.2026
Instagram

SAP fixes CVSS 10.0 Commerce Cloud Data Hub Adapter flaw

Open the post on Instagram ↗