Affected Systems

SAP Commerce Cloud (Data Hub Adapter). All unpatched versions are affected. The vulnerability impacts the default authentication client and certain functions lacking input validation.

Exploitation Status

Patches released by SAP in August 2026 update. No evidence of active exploitation mentioned. Exploitation requires submitting specially crafted input to vulnerable endpoints with insufficient authorization checks.

Business Impact

Maximum severity (CVSS 10.0) unauthenticated remote code execution vulnerability. Attackers can abuse default authentication client to execute arbitrary code and compromise internal components. High impact to confidentiality, integrity, and availability. Organizations running SAP Commerce Cloud face immediate risk of full system compromise without authentication barriers.

Urgency

🔴 Immediate

Recommended Actions

  • Apply SAP August 2026 patches immediately and re-deploy updated SAP Commerce Cloud version
  • Configure IP Filter Set to restrict access to vulnerable Data Hub Adapter endpoints as temporary mitigation if patching is delayed
  • Verify default authentication clients are properly secured or disabled if not required
  • Monitor SAP Commerce Cloud access logs for unusual unauthenticated requests to Data Hub Adapter functions
  • Review and harden network segmentation to limit exposure of SAP Commerce Cloud instances to untrusted networks