Vulnerable Without Authentication

SAP Patch Day: Commerce Cloud Vulnerability Receives Maximum Severity Rating

SAP Patch Day, SAP August Patch Day 2026, SAP August Patch Day 2026 security vulnerabilities, SAP Commerce Cloud CVE-2026-58231, SAP vulnerabilities, CVE-2026-58231, SAP Commerce Cloud, CVE-2026-44772, CVE-2026-44758, CVE-2026-34265
Facebook
X
LinkedIn
Reddit
WhatsApp

For its August Patch Day, SAP has released 28 new security notes and updated two previously published advisories. One of the vulnerabilities received the maximum possible CVSS score of 10.0.

The most severe issue affects the Data Hub Adapter in SAP Commerce Cloud and is tracked as CVE-2026-58231. The vulnerability is caused by an authorization check flaw. Successful exploitation allows attackers to bypass authentication without logging in first. According to SAP’s patch notes, the vulnerability may also allow code execution and access to internal system components. This puts the confidentiality, integrity, and availability of the application at risk.

Ad

MII: Two Paths to Code Execution

SAP is also addressing two additional critical vulnerabilities in Manufacturing Integration and Intelligence (MII). Both are caused by improper input validation in specific servlets. CVE-2026-44772 has a CVSS score of 9.9, while CVE-2026-44758 is rated 9.1.

In both cases, attackers can craft malicious input that ultimately causes arbitrary commands to be executed on the server. Under the worst-case scenario, this could result in a complete compromise of the underlying infrastructure. According to SAP security specialist Onapsis, the key difference between the two vulnerabilities is the level of access required: only one of them requires attackers to already have elevated privileges.

Memory Flaw Exploitable Without Login

The fourth critical vulnerability affects the Application Server ABAP for NetWeaver and the ABAP Platform. Listed as CVE-2026-34265 and rated 9.8, the flaw is caused by logic errors in the processing of the DIAG protocol. Unlike the previously mentioned vulnerabilities, this issue can be exploited without any authentication. Potential consequences include the theft of sensitive data or causing the system to crash.

Ad

Update to a Previous Advisory

Alongside the new vulnerabilities, SAP has also revised a security note originally published in July. At the time, the company had already fixed a critical memory corruption vulnerability in the NetWeaver Application Server ABAP. The latest version of the advisory now provides additional information about the issue.

Eight High-Severity Vulnerabilities

Eight additional vulnerabilities are rated high in severity. They affect the ABAP Developer Tools, Commerce Cloud, Change and Transport System Attach Tool, BusinessObjects, MII, and the Business AI Platform, specifically its Approuter component. The reported issues include privilege escalation, buffer overflows, remote code execution, credential exposure, directory traversal, and missing authorization checks. The Approuter advisory alone covers 11 individual vulnerabilities.

The remaining vulnerabilities addressed in the August Patch Day are rated medium or low risk. SAP says it is currently unaware of any of the vulnerabilities being actively exploited in the wild.

(Editorial Team)

Ad

Artikel zu diesem Thema

Weitere Artikel