Authorization Bypass Vulnerability in SAP NetWeaver and S/4HANA
CVE-2026-0484
6.5MEDIUM
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 10 February 2026
What is CVE-2026-0484?
The security concern arises from a missing authorization check in SAP NetWeaver Application Server ABAP and SAP S/4HANA. This flaw allows authenticated attackers to access specific transaction codes, potentially enabling unauthorized modifications of text data within the system. While this vulnerability does not affect data confidentiality or availability, it poses a significant risk to the integrity of the application, necessitating immediate attention and remediation.
Affected Version(s)
SAP NetWeaver Application Server ABAP and SAP S/4HANA SAP_BASIS 700
SAP NetWeaver Application Server ABAP and SAP S/4HANA SAP_BASIS 701
SAP NetWeaver Application Server ABAP and SAP S/4HANA SAP_BASIS 702