SAP Commerce Cloud (Data Hub Adapter) CVE-2026-58231 patch release
Security Patch Release
Summary
Hide ▲
Show ▼
SAP released patches for Commerce Cloud (Data Hub Adapter) to fix CVE-2026-58231, a CVSS 10.0 flaw that could let an unauthenticated attacker reach arbitrary code execution. The issue stems from insufficient authorization checks and input validation failures in vulnerable functions. Onapsis urged customers to move to a fixed Commerce Cloud release and re-deploy the updated version. A temporary IP Filter Set workaround can restrict access to the vulnerable endpoint until patching is complete.
Related Happenings
SAP July 2026 security updates
Security Patch Release
H score31
First: 14.07.2026 14:42
Last: 14.07.2026 14:42
Sources 1
About this happening:
SAP's July 2026 security updates address 16 vulnerabilities across NetWeaver, Commerce Cloud, and AppRouter, including three critical flaws. The release closes a *...
SAP July 2026 security updates
Security Patch ReleaseAbout this happening: SAP's July 2026 security updates address 16 vulnerabilities across NetWeaver, Commerce Cloud, and AppRouter, including three critical flaws. The release closes a *...
SAP July 2026 security patch day
Security Patch Release
H score40
First: 14.07.2026 14:17
Last: 14.07.2026 14:17
Sources 1
About this happening:
SAP released 19 new and updated security notes for its July 2026 security patch day, covering NetWeaver, Approuter, Commerce Cloud, and other products with...
SAP July 2026 security patch day
Security Patch ReleaseAbout this happening: SAP released 19 new and updated security notes for its July 2026 security patch day, covering NetWeaver, Approuter, Commerce Cloud, and other products with...
SAP June 2026 Security Patch package for NetWeaver and Commerce Cloud
Security Patch Release
H score24
First: 09.06.2026 22:36
Last: 09.06.2026 22:36
Sources 1
About this happening:
SAP released fixes for 15 vulnerabilities in its June 2026 Security Patch package, including four critical flaws in SAP NetWeaver and SAP Commerce Cloud th...
SAP June 2026 Security Patch package for NetWeaver and Commerce Cloud
Security Patch ReleaseAbout this happening: SAP released fixes for 15 vulnerabilities in its June 2026 Security Patch package, including four critical flaws in SAP NetWeaver and SAP Commerce Cloud th...
Cisco Secure Workload REST API patch release (CVE-2026-20223)
Security Patch Release
H score55
First: 22.05.2026 08:36
Last: 22.05.2026 08:36
Sources 1
About this happening:
Cisco patched CVE-2026-20223, a CVSS 10.0 Secure Workload REST API flaw that could expose sensitive data and allow configuration changes across tenant boundaries. The upda...
Cisco Secure Workload REST API patch release (CVE-2026-20223)
Security Patch ReleaseAbout this happening: Cisco patched CVE-2026-20223, a CVSS 10.0 Secure Workload REST API flaw that could expose sensitive data and allow configuration changes across tenant boundaries. The upda...
Ivanti security patch release for CVE-2026-8043
Security Patch Release
H score25
First: 18.05.2026 13:54
Last: 18.05.2026 13:54
Sources 1
About this happening:
Ivanti, Fortinet, SAP, Broadcom, and n8n released security fixes on 2026-05-18 for flaws that could enable authentication bypass, remote code execution, SQL...
Ivanti security patch release for CVE-2026-8043
Security Patch ReleaseAbout this happening: Ivanti, Fortinet, SAP, Broadcom, and n8n released security fixes on 2026-05-18 for flaws that could enable authentication bypass, remote code execution, SQL...
Timeline
-
12.08.2026 10:31 2 articles · 2h ago
SAP releases patches for CVE-2026-58231 in Commerce Cloud (Data Hub Adapter)
Initial DisclosureSAP released patches for CVE-2026-58231, a maximum-severity 10.0 flaw in Commerce Cloud (Data Hub Adapter) that allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to functions with insufficient validation, potentially leading to arbitrary code execution and compromise of internal components. Onapsis advised customers to patch to a fixed Commerce Cloud release, re-deploy the updated version, and temporarily restrict access to the vulnerable endpoint with an IP Filter Set.
Show sources
- SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code — thehackernews.com — 12.08.2026 10:31
- SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code — thehackernews.com — 12.08.2026 10:31