Threat Advisory

SAP Commerce Cloud Flaw Grants Arbitrary File Read Access

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Critical
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities affecting SAP_SE versions The critical flaws hit widely deployed releases have been identified in SAP products, including SAP Commerce Cloud, SAP Manufacturing Integration and Intelligence, SAP NetWeaver / ABAP Platform, and others. The vulnerabilities pose a significant risk to impacted systems, allowing for code injection, remote code execution, privilege escalation, and memory corruption. Affected versions include SAP Commerce Cloud COM_CLOUD 2211 and 2211-JDK21, XMII 15.4 and 15.5, NetWeaver kernel versions from 7.22 through 9.19.

CVE-2026-58231 (CVSS 10 — Critical): An improper authorization issue in SAP Commerce Cloud allows for code injection and remote code execution.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities affecting SAP_SE versions The critical flaws hit widely deployed releases have been identified in SAP products, including SAP Commerce Cloud, SAP Manufacturing Integration and Intelligence, SAP NetWeaver / ABAP Platform, and others. The vulnerabilities pose a significant risk to impacted systems, allowing for code injection, remote code execution, privilege escalation, and memory corruption. Affected versions include SAP Commerce Cloud COM_CLOUD 2211 and 2211-JDK21, XMII 15.4 and 15.5, NetWeaver kernel versions from 7.22 through 9.19.

CVE-2026-58231 (CVSS 10 — Critical): An improper authorization issue in SAP Commerce Cloud allows for code injection and remote code execution.[emaillocker id="1283"]

CVE-2026-34265 (CVSS 9.8 — High): A memory corruption bug in the NetWeaver ABAP kernel allows for code injection and system crashes.

CVE-2026-44772 (CVSS 9.9 — High): A code injection flaw in SAP Manufacturing Integration and Intelligence enables remote code execution.

CVE-2026-44758 (CVSS 9.1 — Medium): A code injection flaw in SAP Manufacturing Integration and Intelligence enables remote code execution.

CVE-2026-58233 (CVSS 7.6 — Low): A remote code execution flaw in the Change and Transport System Attach Tool enables code injection.

CVE-2026-58243 (CVSS 8.8 — Medium): A privilege escalation bug in the SAP ABAP Developer Tools allows for unauthorized access. These vulnerabilities collectively present a significant risk to impacted systems, administrators should apply the relevant security notes without delay. These vulnerabilities collectively present a significant risk to impacted systems, administrators should apply the relevant security notes without delay.

These vulnerabilities collectively present a significant risk to impacted systems, administrators should apply the relevant security notes without delay.

RECOMMENDATION:

We recommend you to refer this link:https://support.sap.com/en/my-support/knowledge-base/security-notes-news/august-2026.html

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu