SAP Commerce Cloud (Data Hub Adapter) CVE-2026-58231 patch release
Security Patch Release
Updated: 12.08.2026 10:31
· First: 12.08.2026 10:31
· 📰 1 src / 1 articles
· H score: 37
SAP released patches for Commerce Cloud (Data Hub Adapter) to fix CVE-2026-58231, a CVSS 10.0 flaw that could let an unauthenticated attacker reach arbitrary code execution. The issue stems from insufficient authorization checks and input validation failures in vulnerable functions. Onapsis urged customers to move to a fixed Commerce Cloud release and re-deploy the updated version. A temporary IP Filter Set workaround can restrict access to the vulnerable endpoint until patching is complete.