SAP’s August batch closes a maximum-severity hole in the Commerce Cloud Data Hub Adapter. Exploitation would hand unauthenticated attackers remote code execution. The issue, CVE-2026-58231, is rated a perfect 10.0 on the CVSS scale.
The root cause is a pairing of weak authorization checks with missing input validation. An unauthenticated attacker can abuse a default authentication client to submit specially crafted input to functions that lack validation, SAP said, leading to arbitrary code execution and compromise of internal components with high impact on confidentiality, integrity, and availability.
Upgrade guidance from Onapsis: install a fixed Commerce Cloud release, then redeploy the platform. Teams that cannot patch yet can shrink the attack surface with an IP Filter Set that restricts access to the vulnerable endpoint.
Three other critical bugs ride along in the August update. CVE-2026-44772 (CVSS 9.9) is a code injection vulnerability in Manufacturing Integration and Intelligence. CVE-2026-34265 (CVSS 9.8) is an out-of-bounds write in Application Server ABAP, exploitable by an unauthenticated attacker through DIAG protocol parsing to corrupt memory. CVE-2026-44758 (CVSS 9.1) is another MII code injection issue tied to a servlet component susceptible to server-side template injection and server-side request forgery.
After the update, teams need to keep the new Secure Transformer system property populated with allowed hosts for XSL files, since the vulnerable servlet will only consume files from those hosts.
