Advisory
SAP takes the security of its vast product portfolio very seriously and thus releases security fixes for
vulnerabilities reported by external researchers and their customers every second Tuesday of the month.
SAP Note 3771065
was released on
11.08.2026 and deals with
"3771065 - [CVE-2026-58231] Improper Authorization in SAP Commerce Cloud (Data Hub Adapter)" within SAP Commerce.
We advice you to follow the instructions, to resolve
missing authentication check
with a
hot news potential for exploitation
in component CEC-SCC-PLA-PL.
According to SAP Security Advisory team a workaround does not exist. It is advisable to implement the correction as monthly patch process.
Risk specification
SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to functions with insufficient validation, enabling arbitrary code execution and compromise of internal components. This can result in full unauthorized access to, modification of, and unavailability of the application.
Solution
Authorization checks have been strengthened, and access to the affected functionality has been restricted.
