# SAP Commerce Cloud critical vulnerability

> Live situation record from CLSTR: https://clstr.news/situations/sap-commerce-cloud-critical-vulnerability
> Updated: 2026-08-15T04:22:24.000Z. Sources: 9. Developments: 2.

SAP identified and released patches for a critical vulnerability in its Commerce Cloud platform, designated as CVE-2026-58231. The flaw, which received a CVSS score of 10.0, resides in the Data Hub Adapter. Due to insufficient authorization checks and inadequate input validation, unauthenticated attackers could potentially execute arbitrary code, leading to full control over the commerce platform.

Following the release of the security updates, researchers observed active exploitation attempts via honeypots. These attacks involve abusing the default authentication client and input validation flaws to achieve remote code execution. While automated mass scanning has been detected, there is currently no public proof of concept, suggesting that attackers may have reverse-engineered the vendor patch. Initial attack traffic has been traced to hosting infrastructure in the United States.

Security researchers at Defused Cyber reported observing the first wave of exploitation attempts just three days after SAP released official security patches. Successful exploitation could grant attackers full administrative control over backend databases, transaction pipelines, and sensitive enterprise assets, impacting the confidentiality, integrity, and availability of global digital storefronts and supply chain operations. 

In response to the active targeting, security firm Onapsis recommends that affected organizations immediately migrate to a fixed Commerce Cloud release. For those unable to patch immediately, implementing an IP Filter Set to restrict access to the vulnerable endpoint is suggested as a temporary mitigation.

## Claims

- CVE-2026-58231 is a maximum-severity vulnerability in SAP Commerce Cloud with a CVSS score of 10.0. (corroborated by 5 sources)
- The vulnerability allows unauthenticated remote code execution (RCE) via the Data Hub Adapter. (corroborated by 5 sources)
- Exploitation attempts against the SAP vulnerability were observed in honeypots three days after the official patch was released. (corroborated by 4 sources)
- There is currently no public proof of concept (PoC) for the CVE-2026-58231 exploit. (corroborated by 2 sources)
- Security firm Onapsis recommends that customers move to a fixed Commerce Cloud release to remediate the flaw. (single source)
- Initial attack traffic was traced to hosting infrastructure in the United States. (single source)

## Timeline

### 2026-08-15: SAP Commerce Cloud vulnerability under active exploitation

Attackers are actively exploiting a critical CVSS 10.0 vulnerability (CVE-2026-58231) in SAP Commerce Cloud, enabling unauthenticated remote code execution just days after a patch was released.

7 sources. https://clstr.news/cluster/sap-commerce-cloud-faces-active-exploitation-of-critical-flaw

### 2026-08-12: SAP patches critical 10.0 severity vulnerability in Commerce Cloud

SAP has patched a critical CVE-2026-58231 vulnerability in Commerce Cloud with a CVSS score of 10.0, which allows unauthenticated attackers to execute arbitrary code via the Data Hub Adapter.

4 sources. https://clstr.news/cluster/sap-patches-critical-100-severity-vulnerability-in-commerce-cloud

---
Cite as: SAP Commerce Cloud critical vulnerability. CLSTR, https://clstr.news/situations/sap-commerce-cloud-critical-vulnerability
