Published on 13 August 2026
An unauthenticated attacker, somewhere on the network, can completely take over a SAP Commerce Cloud instance – without a password, without anyone clicking a link, and with comparatively little effort. This is exactly what SAP describes for the security vulnerability CVE-2026-58231, which the company rated on 11 August 2026 with the highest possible severity: CVSS 10.0. It doesn't get any higher on this scale. Anyone operating an affected SAP Commerce Cloud environment should not put off reading this article.
As part of its August Patch Day, SAP published Security Note 3771065 and used it to close a critical vulnerability in SAP Commerce Cloud. The component specifically affected is the so-called Data Hub Adapter – the component that connects SAP Commerce Cloud with the SAP Data Hub, i.e. the system that prepares and imports data for the shop.
According to SAP, the flaw allows an unauthenticated attacker – that is, someone who does not need to log in – to abuse a default authentication client and send specially crafted input to functions whose input validation is insufficient. The result: arbitrary code execution and thus full control over the instance. In the language of classification, this is a Code Injection (CWE-94), meaning the injection and execution of external program code.
SAP itself puts it soberly but unmistakably in its CVE record:
„SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation.“ (SAP SE, CVE-Record)
The technical scoring vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. Translated, this means:
This combination – network attack, without login, without user action, with maximum impact – is exactly the profile that attackers prefer and that lends itself well to automation.
Important for context, so that no unnecessary alarm arises here: Not every website and not every Commerce Cloud usage is affected. A normal corporate website without SAP Commerce Cloud has nothing to do with this vulnerability.
According to SAP and CVE.org, only the release lines COM_CLOUD 2211 and 2211-JDK21 in the context of the Data Hub Adapter are affected. The Data Hub Adapter comes into play when Data Hub prepares and imports data for your Commerce Cloud installation.
Important note on figures: In the freely available sources there is no reliable information on the number of exposed instances, affected companies, compromised data records or confirmed victims. Where you read "installations: 0" in technical records, this means "not publicly quantified" – not "zero installations". We deliberately do not speculate here.
As of 12 August 2026, there is no confirmed indication of active exploitation in the public sources reviewed. There is no public proof of concept (i.e. no freely available example exploit), no known compromised installations and no entry in the CISA KEV catalog, the US directory of demonstrably exploited vulnerabilities.
This is expressly not an all-clear. "No confirmed exploitation" only means: as of the cut-off date, nothing was detected in the public sources. It does not mean that no exploitation has taken place or can take place. Because of network attack without login, low complexity and maximum score, every affected instance should be treated as an urgent patch case.
As a reminder of why this is not a theoretical risk: the technically comparable SAP case CVE-2025-31324 (SAP NetWeaver) was published in April 2025, added to the CISA KEV catalog as early as 29 April 2025 and, according to the Canadian Cyber Centre, had already been actively exploited since March 2025. This does not prove exploitation of the vulnerability discussed here, but it clearly shows: critical SAP vulnerabilities are quickly seized upon by attackers.
„Customers must patch to the fixed Commerce Cloud release levels referenced in the note and re-build/re-deploy the updated SAP Commerce Cloud version.“ (Thomas Fritsch, Onapsis)
„As a temporary workaround, customers can reduce their exposure by configuring an IP Filter Set in SAP Commerce Cloud to restrict access to the vulnerable endpoint.“ (Thomas Fritsch, Onapsis)Important: This measure reduces exposure but does not replace the patch.
The following section is general information and not legal advice.
The mere existence of CVE-2026-58231 is not yet a GDPR data breach. A personal data breach under Art. 4 No. 12 GDPR only exists once a security breach actually leads to unauthorised access, unauthorised disclosure, loss, alteration or destruction of personal data.
In the case of a successful takeover of a Commerce instance, this is precisely a plausible scenario to examine: shops typically process customer, account, order, address or payment-related data. The controller must then assess the risk to the rights and freedoms of the data subjects.
How seriously supervisory authorities take insufficient technical and organisational measures is shown – as a German point of reference, not as a precedent for this CVE – by an older case: in 2019 the BfDI imposed a fine of 9,550,000 euros on 1&1 Telecom because it considered the authentication measures insufficient and saw a risk to the entire customer base. The matter concerned telephone authentication and not SAP Commerce Cloud, but it underlines the regulatory significance of Art. 32 GDPR.
The general threat situation remains high. The BSI rates the German IT security situation for the period 1 July 2024 to 30 June 2025 as tense and reports 950 ransomware attacks reported to the BKA. ENISA evaluated a total of 4,875 incidents for its Threat Landscape 2025; the exploitation of vulnerabilities was a significant path to initial access at 21.3%. These are general EU and Germany classifications, not statistics specifically on SAP Commerce Cloud – but they show the environment in which a CVSS 10 vulnerability must be placed.
CVE-2026-58231 is one of the most severe categories of vulnerabilities: from the network, without login, without user interaction, with full control as a possible outcome – rated with the maximum value of CVSS 10.0. Specifically affected are the SAP Commerce Cloud release lines COM_CLOUD 2211 and 2211-JDK21 in the context of the Data Hub Adapter, not just any website.
Even if no active exploitation has been publicly confirmed so far: do not wait for it. SAP unmistakably recommends applying the patches via the support portal as a priority. Clarify today whether you are affected, apply the fixed release levels named in SAP Security Note 3771065, rebuild the instance and re-deploy it – and document every step. Until the patch is in place, an IP Filter Set limits the exposure. And if there are signs of unauthorised access, immediately activate your data protection and incident response process. With a vulnerability of this magnitude, speed is decisive.