#7
The Hacker News
general
August 12, 2026 at 07:31 UTC
SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code
By [email protected] (The Hacker News)
AI Summary
SAP patched CVE-2026-58231 (CVSS 10.0), a maximum-severity flaw in Commerce Cloud's Data Hub Adapter stemming from insufficient authorization checks and input validation that allows unauthenticated remote code execution. The August SAP Security Patch Day included 28 new notes, with four addressing critical-severity bugs across multiple enterprise products.
Relevance score: 83.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →