🔴 Critical | Source: The Hacker News
SAP has patched a maximum-severity vulnerability (CVE-2026-58231, CVSS 10.0) in Commerce Cloud’s Data Hub Adapter that allows unauthenticated attackers to execute arbitrary code. The flaw stems from insufficient authorisation checks and input validation, meaning no credentials are required to exploit it. This represents a critical risk for any organisation running SAP Commerce Cloud in production.
Security Architect’s Take: Apply SAP’s patch immediately — a CVSS 10.0 unauthenticated RCE with no prerequisite access is as bad as it gets. Until patched, consider placing WAF rules or network-level controls in front of the Data Hub Adapter endpoint to restrict access to trusted IP ranges only.
Original advisory: SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code