Summary
CVE-2026-58231 is a critical code injection vulnerability (CWE-94) in the Data Hub Adapter of SAP Commerce Cloud. An unauthenticated, network-based attacker can abuse a default authentication client to submit specially crafted input to vulnerable functions, resulting in arbitrary code execution. It carries a CVSS v3.1 base score of 10.0 (Critical).
Technical details
- Root cause: Improper control of generation of code (CWE-94) in the SAP Commerce Cloud Data Hub Adapter, reachable via a default authentication client.
- Trigger conditions: An attacker abuses the default authentication client and submits specially crafted input to vulnerable functions; no authentication or user interaction is required.
- Attack vector: Network (AV:N), low attack complexity, no privileges required.
- Impact: Arbitrary code execution with full compromise of confidentiality, integrity, and availability, including impact on internal components (scope change).
Affected software
- SAP Commerce Cloud (Data Hub Adapter) — COM_CLOUD 2211
- SAP Commerce Cloud (Data Hub Adapter) — COM_CLOUD 2211-JDK21
Severity
- CVSS v3.1 Base Score: 10.0 (Critical)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: Apply the fix delivered in SAP Security Note 3771065 as part of the August 2026 SAP Security Patch Day. Update affected COM_CLOUD 2211 and 2211-JDK21 deployments to the patched release and, where applicable, rebuild and redeploy SAP Commerce Cloud.
- If no patch can be applied immediately: Restrict network access to the Data Hub Adapter so it is not reachable from untrusted networks, and review use of the default authentication client per SAP’s guidance.
How IONIX identifies potentially affected assets
IONIX matches the following signals against data already collected when it crawled the asset; identifying the technology sends no request beyond that crawl.
- Raw response body: paths containing
/sys_master/,/hybr/,/_ui/…/desktop/, or/_ui/…/common/; a<script>tag referencing ahybris….jsfile.

