CVE-2026-58231 is an unauthenticated, CVSS 10.0 code execution bug in Commerce Cloud's Data Hub Adapter. Defused says attempts hit its honeypots three days after patch day.
Perspective Coverage
5 publishers
- Builder
- Builder 26%
- Operator
- Operator 65%
- Investor
- Investor 9%
Reality
- Evidence70
- Adoption55
- Hype gap+25
- Incentives40
- Confidence68
Onapsis, which found the flaw alongside SAP, rates it CVSS 10.0 and recommends immediate patching. A second kernel note in the same batch reaches every S/4HANA 2025 system and any older release already on a current kernel.
Publishers:onapsis.com
Reality
- Evidence55
- Adoption20
- Hype gap+25
- Incentives75
- Confidence48
Five HotNews and nine High Priority notes land on Commerce Cloud, NetWeaver AS ABAP and MII, and two of the described fixes are not finished when the patch is applied.
Publishers:onapsis.com
Reality
- Evidence62
- Adoption25
- Hype gap+12
- Incentives72
- Confidence55
CVE-2026-58231 chains a default auth client with missing input validation in SAP's Data Hub Adapter. The fix needs a rebuild and redeploy; the attackers needed 72 hours.
Reality
- Evidence42
- Adoption28
- Hype gap+12
- Incentives38
- Confidence44
CVE-2026-58231 lets an unauthenticated attacker reach code execution via the Data Hub Adapter. Onapsis says the fix is patch then re-deploy, with an IP filter set as the stopgap.
Reality
- Evidence70
- Adoption18
- Hype gap+8
- Incentives55
- Confidence62