Enterprise e-commerce operations running SAP Commerce Cloud face a critical security risk following the discovery of a maximum-severity arbitrary code execution flaw. The vulnerability, tracked under CVE-2026-58231, carries a maximum CVSS rating of 10.0 and allows unauthenticated attackers to remotely execute arbitrary code on affected systems by abusing weak default authentication settings and improperly validated input handling in the platform’s Data Hub Adapter.
The fix was published as part of SAP’s August 2026 patch updates, which also address three other critical vulnerabilities impacting core enterprise management systems, including SAP Manufacturing Integration and Intelligence (MII) and SAP NetWeaver ABAP platforms.
Critical RCE in SAP Commerce Cloud Data Hub
The most severe flaw addressed in the patch round is CVE-2026-58231, affecting the Data Hub Adapter component of SAP Commerce Cloud. According to security research from cybersecurity firm Onapsis, the core issue lies in insufficient authorization checks combined with inadequate input validation.
The vulnerability allows an unauthenticated, remote attacker to exploit a default authentication client built into the application. By sending specially crafted inputs to specific endpoints and functions that lack robust validation, attackers can trigger arbitrary code execution on the server running the Commerce Cloud application.
In enterprise environments, SAP Commerce Cloud Data Hub acts as the integration engine responsible for staging, transforming, and syncing large volumes of operational data—such as customer records, pricing tables, product catalogs, and order updates—between e-commerce storefronts and central backend enterprise resource planning (ERP) solutions like SAP S/4HANA. Because the Data Hub component routinely interfaces with exposed channels and core databases, achieving code execution at this layer provides attackers with full system privileges over the host, severely compromising system confidentiality, data integrity, and service availability.
Memory Corruption in ABAP and Flaws in SAP MII
SAP’s August 2026 update also addresses three additional critical vulnerabilities across different products in its portfolio:
- CVE-2026-34265 (CVSS 9.8): An out-of-bounds write flaw in Application Server ABAP for SAP NetWeaver and ABAP Platform. Unauthenticated remote attackers can exploit logical errors during the application’s parsing of the DIAG protocol—the binary presentation protocol used for communications between SAP GUI software and application servers. Exploiting this memory corruption flaw can lead to sensitive memory disclosure or cause the entire application server to crash, resulting in a full denial of service.
- CVE-2026-44772 (CVSS 9.9): A code injection vulnerability in SAP Manufacturing Integration and Intelligence (MII). A low-privileged attacker can supply malicious input to a vulnerable servlet, causing the application to retrieve and process external XML and XSL transformation files from an attacker-controlled source. This Server-Side Request Forgery (SSRF) and untrusted content processing path ultimately results in arbitrary command execution on the underlying host operating system.
- CVE-2026-44758 (CVSS 9.1): A separate code injection flaw in SAP MII caused by Server-Side Template Injection (SSTI) and SSRF weaknesses within an active servlet component. High-privileged users could leverage this vector to execute arbitrary OS commands.
Impact and Realistic Blast Radius
The security issues patched in this update pose a serious threat to enterprise environments. SAP Commerce Cloud powers B2B and B2C digital commerce portals for major global corporations. An unauthenticated CVSS 10.0 vulnerability on an internet-facing or perimeter-accessible e-commerce backend provides initial access brokers and threat actors with an ideal entry point to establish persistence without requiring credentials or phishing campaigns. Once executed, malicious code can be used to exfiltrate payment records, steal customer personal data, or pivot directly into connected core ERP systems.
Meanwhile, vulnerabilities in SAP MII present unique operational risks to industrial environments. SAP MII bridges enterprise-level IT planning systems with operational technology (OT) networks, manufacturing execution systems (MES), and plant automation tools. Command execution on an MII host can allow attackers to manipulate production telemetry, disrupt supply chain scheduling, or compromise the integrity of automated manufacturing processes.
Patching and Mitigation Steps
SAP administrators should immediately review and deploy the relevant August 2026 updates across production and development environments:
- SAP Commerce Cloud (CVE-2026-58231): Upgrade to a patched Commerce Cloud release and re-deploy the updated SAP Commerce Cloud application instance. If immediate patching and deployment cannot be performed, administrators should deploy an IP Filter Set to restrict network access to the vulnerable Data Hub Adapter endpoint to trusted management hosts only.
- SAP MII (CVE-2026-44772): Apply the SAP patch and manually configure the new
Secure Transformersystem property with an explicit whitelist of allowed domain hosts permitted to supply XSL files to the application. - SAP MII (CVE-2026-44758): Apply the patch, which permanently removes the vulnerable servlet component from the installation.
- SAP NetWeaver ABAP Platform (CVE-2026-34265): Update Application Server ABAP instances to install patched DIAG protocol parsing libraries.
Related content
SAP August 2026 Patch Day Addresses Critical Auth Bypass and Code Execution
Security NewsCritical SAP NetWeaver ABAP Flaw (CVE-2026-44747) Poses High Risk to Enterprises
Security NewsBlack Hat USA 2026 Vendor Wrap-Up: Focus Turns to Agentic AI and Virtual Patching
Security NewsBlack Hat USA 2026: AI Agents, Continuous SecOps, and Exposure Management Take Center…
Found something similar in your stack?
Let's find out before it becomes an incident.
Book an advisory call