SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code
Summary
Public reporting describes CVE-2026-58231, a maximum-severity (CVSS 10.0) unauthenticated remote code execution issue in SAP Commerce Cloud (formerly Hybris), specifically an improper-authorization weakness in the core Data Hub Adapter. SAP patched it on the August Patch Day (security note 3771065); this memo synthesizes those reports and does not reflect independent reverse engineering. Defused reported honeypot hits three days after patch day; SAP told BleepingComputer it is aware and investigating, and has not itself labeled the flaw actively exploited in the advisory.
Attack vector
The reachable surface is internet-facing SAP Commerce Cloud, including the Data Hub Adapter extension. An unauthenticated attacker can abuse a default authentication client and send crafted input to insufficiently validated functions (SAP, via BleepingComputer). No privileges are required and attack complexity is described as low. Shadowserver has fingerprinted 4,200+ IPs as Commerce Cloud, concentrated in Europe and North America; how many are still vulnerable versus honeypots or already patched is not stated.
Exploit
Bug class is improper authorization in the Data Hub Adapter, combined with missing validation on certain functions after the attacker uses a default authentication client (SAP). Successful abuse yields arbitrary code execution and compromise of internal application components, with high impact on confidentiality, integrity, and availability. Sources do not name the exact endpoints, payload format, or deserialization/injection primitive. BleepingComputer/Defused state there is no public PoC.
In the wild / novelty
Disclosure: SAP August Patch Day; note 3771065. Exploitation: Defused reported first attempts against CVE-2026-58231 hitting their honeypots three days after patch day (tweet cited by BleepingComputer), and noted the issue had no public PoC and was not previously known to be exploited. That is honeypot targeting, not confirmed victim compromise. SAP’s advisory had not flagged in-the-wild use; a spokesperson said SAP is investigating Defused’s report.
Risk
Affected product is SAP Commerce Cloud / Hybris used by large retailers and global brands. Successful RCE can take over storefront/backend application components (customer data, orders, integrations). Blast radius is any unpatched, reachable Commerce Cloud instance with the vulnerable Data Hub Adapter path; Shadowserver’s 4,200+ fingerprints indicate a large internet-visible estate, but exposure ≠ confirmed vulnerability.
Remediation
Apply SAP security note 3771065 immediately (SAP spokesperson via BleepingComputer; NCSC-NL title also points at Data Hub Adapter fixes). Hunt for unauthenticated or anomalous Data Hub Adapter traffic and for use of default authentication clients; treat post-patch-day probes as likely opportunistic scanning (Defused). Validate patch level on all Commerce Cloud / Data Hub Adapter deployments; do not assume cloud-hosted instances are auto-fixed unless SAP/customer process confirms it. Shadowserver fingerprints can help inventory internet-facing nodes, then confirm patch status separately.
CVE / identifiers
CVE-2026-58231; SAP security note 3771065 (hxxps://me[.]sap[.]com/notes/3771065); NCSC-2026-0302; CWE not stated (described as improper authorization / insufficient validation).
Confidence
medium — vendor quotes and CVE/note IDs are consistent across BleepingComputer and the NCSC title, but The Hacker News and NCSC bodies did not yield usable technical text, and exploit mechanics beyond “default auth client + crafted input” are not specified.
Open questions
Exact functions, request paths, and input format are unpublished. Whether Defused hits are weaponized RCE or only probes is unknown. SAP has not confirmed exploitation. Count of actually vulnerable (vs. fingerprinted or already patched) instances is unknown. Whether a public PoC has appeared after these articles is not stated in the cluster.
Sources
- SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code (The Hacker News)
- Max severity SAP Commerce Cloud flaw now targeted in attacks (BleepingComputer)
- NCSC-2026-0302 [1.00] [M/H] Kwetsbaarheden verholpen in SAP Commerce Cloud Data Hub Adapter (NCSC-NL Advisories)