SAP Commerce Cloud CVE-2026-58231 Requires Urgent Patching
ID: 1ff91959-65f6-5595-a8cb-a88b229cdcf7
STIX ID: report--1ff91959-65f6-5595-a8cb-a88b229cdcf7
Feed Name: SOCRadar Blog
SAP has released an urgent advisory for CVE-2026-58231, a critical (CVSS 10.0) improper-authorization vulnerability in the SAP Commerce Cloud Data Hub Adapter that can enable unauthenticated remote arbitrary code execution; affected branches include COM_CLOUD 2211 and COM_CLOUD 2211-JDK21 and organizations should apply SAP Security Note 3771065, redeploy corrected releases, verify running versions, restrict external access to the Data Hub import endpoint, and review logs and credentials—exploitation attempts have been observed in honeypots but no confirmed successful exploit or public proof-of-concept has been published.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
