---
schema: 1
kind: vulnerability
title: >
  CVE-2026-58231 — SAP Commerce Cloud: an unauthenticated request to the Data Hub Adapter import
  endpoint reaches arbitrary code execution (CVSS 10.0), and the fix needs a rebuild and redeploy
headline: >
  SAP's August patch day is led by a CVSS 10.0 pre-auth code-execution flaw in the Commerce Cloud
  Data Hub Adapter, fixed only by a rebuild and redeploy
summary: >
  SAP's 2026-08-11 Security Patch Day fixes CVE-2026-58231, an improper-authorization flaw in the
  SAP Commerce Cloud Data Hub Adapter that Onapsis describes as insufficient authorization checks
  and input validation reachable without authentication, rated CVSS 10.0 and capable of arbitrary
  code execution. Further notes cover code injection in SAP Manufacturing Integration and
  Intelligence (CVE-2026-44772, 9.9; CVE-2026-44758, 9.1) and an unauthenticated memory-corruption
  flaw in the NetWeaver AS ABAP kernel's DIAG protocol parser (CVE-2026-34265, 9.8). No
  exploitation is reported by any party; Commerce Cloud fixes require rebuilding and redeploying
  the release rather than installing a patch, and an IP filter set is the vendor-side interim
  control.
discovered_at: "2026-08-12T04:45:00Z"
updated_at: "2026-08-16T04:35:00Z"
event_date: 2026-08-11
run_id: 2026-08-12T0411Z-intel
priority: high
immediate_action: null
tags:
  - vulnerabilities
  - rce
  - pre-auth
  - patch-available
  - info-disclosure
  - actively-exploited
regions:
  - global
  - europe
sectors:
  - public-sector
  - finance
  - manufacturing
  - retail
entities: []
techniques:
  - T1190
  - T1059
  - T1078.001
affected_products:
  - SAP Commerce Cloud
  - SAP Manufacturing Integration and Intelligence
  - SAP NetWeaver Application Server ABAP
  - SAP ABAP Platform
  - SAP ABAP Developer Tools
cves:
  - id: CVE-2026-58231
    cvss: "10.0"
    epss: null
    type: rce
    vector: zero-click
    auth: pre-auth
    status:
      - exploited
      - patch-available
      - mitigation-only
    affected: SAP Commerce Cloud (Data Hub Adapter) — see SAP Security Note 3771065 for the release levels
    fixed: >
      Fixed Commerce Cloud release levels per SAP Security Note 3771065; takes effect only after a
      rebuild and redeploy
  - id: CVE-2026-44772
    cvss: "9.9"
    epss: null
    type: rce
    vector: zero-click
    auth: post-auth
    status:
      - patch-available
    affected: SAP Manufacturing Integration and Intelligence — see SAP Security Note 3765948
    fixed: >
      Per SAP Security Note 3765948; the patch does NOT remove the vulnerable servlet — after
      applying it, customers must additionally configure and maintain the new "Secure Transformer"
      system property with a list of allowed hosts for XSL files, or the servlet remains reachable
  - id: CVE-2026-44758
    cvss: "9.1"
    epss: null
    type: rce
    vector: zero-click
    auth: post-auth
    status:
      - patch-available
    affected: SAP Manufacturing Integration and Intelligence — see SAP Security Note 3758900
    fixed: "Per SAP Security Note 3758900; the patch removes the vulnerable servlet component"
  - id: CVE-2026-34265
    cvss: "9.8"
    epss: null
    type: memory-corruption
    vector: zero-click
    auth: pre-auth
    status:
      - patch-available
    affected: >
      KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT, 7.22EXT2, 7.22EXT3, 7.53, 7.54, 7.77, 7.89,
      7.93, 8.04, 9.16, 9.18, 9.19, KERNEL 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 8.04, 9.16, 9.18, 9.19
    fixed: Per SAP Security Note 3714806
  - id: CVE-2026-58243
    cvss: "8.8"
    epss: null
    type: priv-esc
    vector: zero-click
    auth: post-auth
    status:
      - patch-available
    affected: SAP ABAP Developer Tools — see SAP Security Note 3772411
    fixed: Per SAP Security Note 3772411
  - id: CVE-2026-42945
    cvss: "8.1"
    epss: null
    type: memory-corruption
    vector: zero-click
    auth: pre-auth
    status:
      - patch-available
    affected: SAP Commerce Cloud in public-cloud deployments with NGINX — see SAP Security Note 3773203
    fixed: "Per SAP Security Note 3773203; requires rebuild and redeploy"
sources:
  - url: "https://support.sap.com/en/my-support/knowledge-base/security-notes-news/august-2026.html"
    publisher: SAP SE (Security Patch Day)
    date: 2026-08-11
    role: primary
  - url: "https://onapsis.com/blog/sap-security-patch-day-august-2026/"
    publisher: Onapsis Research Labs
    date: 2026-08-11
    role: corroborating
  - url: "https://security-hub.ncsc.admin.ch/#/posts/12839"
    publisher: NCSC Switzerland — Cyber Security Hub
    date: 2026-08-11
    role: corroborating
  - url: "https://advisories.ncsc.nl/2026/ncsc-2026-0302.html"
    publisher: NCSC-NL (Nationaal Cyber Security Centrum)
    date: 2026-08-15
    role: primary
  - url: "https://www.bleepingcomputer.com/news/security/max-severity-sap-commerce-cloud-flaw-now-targeted-in-attacks/"
    publisher: BleepingComputer
    date: 2026-08-14
    role: corroborating
closed_sources: []
evidence:
  - quote: Logical errors in DIAG protocol parsing allow an unauthenticated attacker to generate memory corruptions.
    publisher: Onapsis Research Labs
  - quote: "As a temporary workaround, customers can reduce their exposure by configuring an IP Filter Set in SAP Commerce Cloud to restrict access to the vulnerable endpoint."
    publisher: Onapsis Research Labs
  - quote: "First exploitation attempts against CVE-2026-58231 (unauth RCE in SAP Commerce Cloud, CVSS 10.0) is now hitting our honeypots - 3 days after patch day,"
    publisher: "Defused, quoted by BleepingComputer"
  - quote: Beveiligingsbedrijf Defused meldt dat kwaadwillenden actief scannen en op zoek zijn naar kwetsbare Data Hub Adapter-systemen.
    publisher: NCSC-NL
  - quote: SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation
    publisher: "SAP, quoted by BleepingComputer"
verification: multi-source
sourcing_note: null
confidence: high
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
classification:
  reliability: A
  credibility: 1
watchlist_hit: false
actions:
  - "Inventory self-managed SAP Commerce Cloud storefronts and apply SAP Security Note 3771065 by rebuilding and redeploying the fixed release — an installed patch is not sufficient for this component; where the redeploy cannot happen this week, restrict access to the Data Hub import endpoint with a Commerce Cloud IP filter set in the interim."
  - Confirm the Data Hub Adapter fix from SAP Security Note 3771065 has actually been rebuilt and redeployed on every internet-reachable Commerce Cloud instance — taking the note without the redeploy leaves the instance exposed — and treat any instance that stayed reachable and unredeployed after 2026-08-14 as owing a compromise assessment rather than only an upgrade.
  - "For any SAP Manufacturing Integration and Intelligence instance patched with Security Note 3765948 (CVE-2026-44772), configure and maintain the new 'Secure Transformer' system property with an explicit allowed-hosts list for XSL files — the patch alone does not remove the vulnerable servlet, and without this property the flaw remains exploitable regardless of patch status."
updates:
  - at: "2026-08-16T04:35:00Z"
    run_id: 2026-08-16T0411Z-intel
    type: update
    summary: >
      CVE-2026-58231, the CVSS 10.0 unauthenticated code-execution flaw in the SAP Commerce Cloud Data
      Hub Adapter covered here on 2026-08-12 as unexploited, is now being attacked:
      Defused recorded the first exploitation attempts hitting its honeypot sensors on 2026-08-14,
      three days after SAP's patch day, and states no public proof-of-concept exists. NCSC-NL
      published advisory NCSC-2026-0302 on 2026-08-15 recording that attackers are actively scanning
      for vulnerable Data Hub Adapter systems. Shadowserver tracks over 4,200 internet-exposed
      instances, most in Europe and North America, and the Commerce Cloud fix only takes effect after
      a rebuild and redeploy — so an instance that merely took the note is still exposed.
    fields:
      - actions
      - cves
      - evidence
      - sources
      - tags
      - techniques
      - body
    merged_from: 2026-08-16/cve-2026-58231-sap-commerce-cloud-exploitation-attempts
  - at: "2026-08-28T05:00:00Z"
    run_id: 2026-08-28T0409Z-intel
    type: correction
    summary: >
      This entry stated that SAP's fix "removes the vulnerable servlet component in both cases" for
      CVE-2026-44772 and CVE-2026-44758. Onapsis's own text says that only of Note 3758900
      (CVE-2026-44758). For Note 3765948 (CVE-2026-44772, CVSS 9.9) the servlet is not removed;
      Onapsis states customers must additionally configure and maintain a new "Secure Transformer"
      system property naming the hosts allowed to serve XSL files to the servlet, or it remains
      reachable. The CVE-2026-44772 record and the body are corrected to name this required
      post-patch step.
    fields:
      - cves
      - body
  - at: "2026-08-28T15:00:00Z"
    run_id: 2026-08-28T1500Z-audit
    type: improvement
    internal: true
    summary: >
      v4.2 migration: updated_at recomputed under the new float rule (only type: update 
      records move updated_at; corrections/improvements no longer re-float the entry).
    fields: [updated_at, body]
migrated_from: null
---

SAP's August 2026 Security Patch Day of 2026-08-11 released 28 new security notes plus one GitHub security advisory, with two updates to previously released notes ([SAP SE, 2026-08-11](https://support.sap.com/en/my-support/knowledge-base/security-notes-news/august-2026.html)); Onapsis, counting the cycle its own way, puts it at thirty-three notes including five HotNews and nine High Priority ([Onapsis Research Labs, 2026-08-11](https://onapsis.com/blog/sap-security-patch-day-august-2026/)). The one that changes an exposure picture rather than a patch schedule is CVE-2026-58231, carried by SAP Security Note 3771065 at CVSS 10.0: an improper-authorization flaw in the Data Hub Adapter of SAP Commerce Cloud. Onapsis, which worked with SAP on eleven of the notes in this cycle, describes the cause as insufficient authorization checks combined with insufficient input validation, and the outcome as arbitrary code execution with compromise of internal components ([Onapsis Research Labs, 2026-08-11](https://onapsis.com/blog/sap-security-patch-day-august-2026/)). The reason this ranks above a routine critical: Commerce Cloud is the platform behind public storefronts, so the vulnerable component sits on the internet side of the estate by design, and the score's pre-auth, no-interaction profile means reaching it takes a crafted request rather than a foothold.

Remediation for this one is not a patch install. Onapsis states customers must patch to the fixed Commerce Cloud release levels referenced in the note and then rebuild and redeploy the updated version, and that the interim exposure reduction available today is an IP filter set restricting access to the vulnerable endpoint ([Onapsis Research Labs, 2026-08-11](https://onapsis.com/blog/sap-security-patch-day-august-2026/)). Any organisation whose change process treats "SAP note applied" as equivalent to "fixed" will record this as remediated while the storefront is still reachable. The same rebuild-and-redeploy requirement applies to CVE-2026-42945 (CVSS 8.1), a buffer overflow affecting Commerce Cloud public-cloud deployments fronted by NGINX, per SAP Security Note 3773203 ([SAP SE, 2026-08-11](https://support.sap.com/en/my-support/knowledge-base/security-notes-news/august-2026.html)).

Three further notes Onapsis classes as HotNews matter to different estates. CVE-2026-44772 (CVSS 9.9, Note 3765948) and CVE-2026-44758 (CVSS 9.1, Note 3758900) are code-injection flaws in SAP Manufacturing Integration and Intelligence reaching arbitrary command execution on the underlying host; Onapsis states the lower score on the second reflects a higher privilege requirement. The two remedies are not the same: for Note 3758900 (CVE-2026-44758) the patch removes the vulnerable servlet component outright, while for Note 3765948 (CVE-2026-44772) the servlet stays in place and customers must additionally configure and maintain a new "Secure Transformer" system property naming the hosts allowed to serve XSL files to it ([Onapsis Research Labs, 2026-08-11](https://onapsis.com/blog/sap-security-patch-day-august-2026/)). CVE-2026-34265 (CVSS 9.8, Note 3714806) is the one to weigh against internal network exposure rather than internet exposure: "Logical errors in DIAG protocol parsing allow an unauthenticated attacker to generate memory corruptions" in the Application Server ABAP kernel, with potential disclosure of sensitive system information or a crash of the instance ([Onapsis Research Labs, 2026-08-11](https://onapsis.com/blog/sap-security-patch-day-august-2026/)). DIAG is the SAP GUI presentation protocol, so the affected listener is one that ordinarily faces user workstations, and the affected kernel list spans KRNL64NUC/KRNL64UC and KERNEL builds from 7.22 through 9.19 ([SAP SE, 2026-08-11](https://support.sap.com/en/my-support/knowledge-base/security-notes-news/august-2026.html)). Rounding out the High Priority set, CVE-2026-58243 (CVSS 8.8, Note 3772411) covers the SQL Console in SAP ABAP Developer Tools, where support for host expressions inside SQL statements let a low-privileged authenticated user run database operations they should not reach.

No party reports exploitation of any of these. That is the reason none of them carries a `critical` priority here — but the Data Hub Adapter flaw still demands action ahead of the normal SAP patch cadence, because its own mechanics set the clock: an unauthenticated, no-interaction path to code execution on a component that is internet-facing by product design, disclosed with a CVSS 10.0 and a documented interim network control, is the shape that gets scanned for within days of a patch day. Detection concepts are ordinary but specific: in web and reverse-proxy access logs, surface requests to the Data Hub import path from source addresses outside the integration ranges that legitimately feed it, and treat any such request that precedes an unexplained child process under the Commerce Cloud application account as an incident rather than an anomaly. Discriminating benign from malicious here is easier than usual — legitimate Data Hub imports arrive from a small, enumerable set of integration sources, so the source address and the calling identity, not the request body, are the useful filter. On the ABAP side, a DIAG-parsing memory-corruption attempt surfaces as work-process crashes or short dumps clustered on one instance rather than as an authentication event.

## Update — 2026-08-16T04:35:00Z

The Commerce Cloud flaw previously recorded here as carrying no exploitation from any party is being attacked. Threat-intelligence firm Defused reported on 2026-08-14 that the first exploitation attempts against CVE-2026-58231 were arriving at its honeypot sensors three days after SAP's 2026-08-11 patch day, and stated in the same report that the vulnerability has no public proof-of-concept ([BleepingComputer, 2026-08-14](https://www.bleepingcomputer.com/news/security/max-severity-sap-commerce-cloud-flaw-now-targeted-in-attacks/)). Those two facts together are the operationally interesting part: whoever is sending these requests built a working exploit without published research to copy, on a three-day clock, against a component whose remediation is slower than a patch install. On 2026-08-15 the Dutch national cyber security centre published advisory NCSC-2026-0302, which records that attackers are actively scanning for and seeking out vulnerable Data Hub Adapter systems ([NCSC-NL, 2026-08-15](https://advisories.ncsc.nl/2026/ncsc-2026-0302.html)).

The mechanism is unchanged from the original entry and is worth restating precisely because it shapes what an exposed request looks like: SAP describes the flaw as allowing an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to functions that lack sufficient validation, reaching arbitrary code execution ([BleepingComputer, 2026-08-14](https://www.bleepingcomputer.com/news/security/max-severity-sap-commerce-cloud-flaw-now-targeted-in-attacks/)). The exposure is real rather than theoretical: Shadowserver tracks over 4,200 IP addresses carrying a SAP Commerce Cloud fingerprint, most of them in Europe and North America, though the same reporting is explicit that it cannot say how many of those are honeypots or already remediated ([BleepingComputer, 2026-08-14](https://www.bleepingcomputer.com/news/security/max-severity-sap-commerce-cloud-flaw-now-targeted-in-attacks/)).

Calibrate the status honestly. What is confirmed is exploitation attempts against sensors ([BleepingComputer, 2026-08-14](https://www.bleepingcomputer.com/news/security/max-severity-sap-commerce-cloud-flaw-now-targeted-in-attacks/)) and scanning for vulnerable systems ([NCSC-NL, 2026-08-15](https://advisories.ncsc.nl/2026/ncsc-2026-0302.html)) — no party reports a compromised production instance, and SAP has not flagged the flaw as exploited in its own advisory ([BleepingComputer, 2026-08-14](https://www.bleepingcomputer.com/news/security/max-severity-sap-commerce-cloud-flaw-now-targeted-in-attacks/)). That distinction matters for triage effort, not for patch priority: the interval between a public fix and a working exploit has collapsed to days on this component, and the remediation is a rebuild-and-redeploy cycle measured in change windows.

Detection, in vendor-neutral terms: in web-access and application logs for the Data Hub Adapter, look for unauthenticated requests to the adapter's import functions that present the default authentication client rather than a customer-provisioned one, and for import-job invocations that do not line up with a scheduled integration run — an import that no ETL schedule accounts for is the anomaly, since this component's legitimate traffic is machine-generated and predictable. Pair that with egress review from the Commerce Cloud application tier, because arbitrary code execution here runs inside a host that normally talks only to its own data-integration peers. Hardening remains the vendor's own path: Onapsis, which works with SAP on its patch cycle, records that customers must patch to the fixed Commerce Cloud release levels referenced in the note and then re-build and re-deploy the updated version, and that configuring an IP Filter Set in Commerce Cloud to restrict access to the vulnerable endpoint is the temporary workaround that reduces exposure meanwhile ([Onapsis, 2026-08-11](https://onapsis.com/blog/sap-security-patch-day-august-2026/)).

## Correction — 2026-08-28T05:00:00Z

The original entry stated that SAP's fix "removes the vulnerable servlet component in both cases" for CVE-2026-44772 (Note 3765948) and CVE-2026-44758 (Note 3758900). Onapsis's own text supports that statement for only one of the two. For Note 3758900 the patch does remove the vulnerable servlet component outright ([Onapsis Research Labs, 2026-08-11](https://onapsis.com/blog/sap-security-patch-day-august-2026/)). For Note 3765948 (CVE-2026-44772, CVSS 9.9) the servlet stays in place, and Onapsis states the required remedy directly: "After implementing the patch, customers need to maintain the new system property 'Secure Transformer' with a list of allowed hosts for hosting XSL files. Only XSL files from these hosts can be consumed by the vulnerable servlet" ([Onapsis Research Labs, 2026-08-11](https://onapsis.com/blog/sap-security-patch-day-august-2026/)).

The practical consequence: an SAP Basis team that applied Note 3765948 and recorded the CVSS 9.9 flaw as remediated, without configuring the Secure Transformer allowed-hosts property, has left the vulnerable servlet reachable — the patch alone does not close the flaw for this note. Teams that patched CVE-2026-44772 should verify the Secure Transformer property is now configured with an explicit allowed-hosts list, not merely that Note 3765948 shows as applied. Nothing about Note 3758900 (CVE-2026-44758) or any other flaw in this entry changes.
