Missing Authorization Check in Application Server ABAP from SAP
CVE-2026-0506
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 13 January 2026
What is CVE-2026-0506?
A Missing Authorization Check vulnerability exists in the Application Server ABAP and ABAP Platform, allowing authenticated attackers to exploit RFC functions. By executing form routines (FORMs) within the ABAP system, attackers can potentially manipulate data accessed through these FORMs and invoke system functionalities, posing significant risks to data integrity and availability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
SAP NetWeaver Application Server ABAP and ABAP Platform SAP_BASIS 700
SAP NetWeaver Application Server ABAP and ABAP Platform SAP_BASIS 701
SAP NetWeaver Application Server ABAP and ABAP Platform SAP_BASIS 702
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved