SAP has announced a crucial update to mitigate a severe security flaw in its Commerce Cloud platform, specifically the Data Hub Adapter. This flaw, identified as CVE-2026-58231, carries a maximum severity score of 10.0 on the CVSS scale, posing a significant threat of arbitrary code execution.
Understanding the Vulnerability
The vulnerability arises from inadequate authorization checks and insufficient input validation. This issue allows an unauthenticated attacker to manipulate a default authentication client and introduce specially crafted inputs into certain functions. The consequences of exploiting this flaw include potential arbitrary code execution, thereby threatening the confidentiality, integrity, and availability of the affected applications.
Security experts from Onapsis emphasize the urgency for users to apply the latest patches for SAP Commerce Cloud. As an interim measure, configuring an IP Filter Set to limit access to vulnerable endpoints is recommended until the fix is fully implemented.
Additional Critical Vulnerabilities in August Update
In addition to the Commerce Cloud flaw, SAP’s August 2026 update addresses three other critical vulnerabilities. One of these, CVE-2026-44772, involves a code injection risk in Manufacturing Integration and Intelligence, with a CVSS score of 9.9. Another, CVE-2026-34265, pertains to an out-of-bounds write issue in Application Server ABAP, scoring 9.8, which could lead to system information exposure or crashes due to errors in DIAG protocol parsing.
Furthermore, CVE-2026-44758, also related to code injection in Manufacturing Integration, poses a threat of arbitrary command execution by attackers with high-level privileges. The patch for this vulnerability removes a servlet component vulnerable to server-side template injection (SSTI) and server-side request forgery (SSRF).
Protecting Your Systems
Onapsis advises that after applying patches, customers should configure a new system property named ‘Secure Transformer’ to permit only certain hosts for XSL file hosting. This measure ensures that only authorized XSL files can be processed by the vulnerable servlet component.
These updates underscore the importance of maintaining up-to-date security measures to protect enterprise systems from potential cyber threats. SAP users are strongly encouraged to implement the recommended patches and precautions promptly to safeguard their infrastructures.
