SECURITYTHE HACKER NEWS
SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code
SAP has released patches addressing a maximum-severity security flaw impacting Commerce Cloud (Data Hub Adapter). This vulnerability, designated CVE-2026-58231 and rated 10.0 on the CVSS scoring system, allows unauthenticated attackers to execute arbitrary code through insufficient authorization checks and input validation.
Mentioned
Related Signal
Adjacent reporting
- SAP fixes critical vulnerabilities in Commerce Cloud and S/4HANA
- SAP warns of critical flaws in NetWeaver and Commerce Cloud
- SAP fixes critical flaws in NetWeaver and Commerce Cloud
- Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution
- Critical Splunk Enterprise Flaw Lets Attackers Run Code Without Authentication