Missing Authorization Check in Application Server ABAP from SAP
CVE-2026-0506

8.1HIGH

What is CVE-2026-0506?

A Missing Authorization Check vulnerability exists in the Application Server ABAP and ABAP Platform, allowing authenticated attackers to exploit RFC functions. By executing form routines (FORMs) within the ABAP system, attackers can potentially manipulate data accessed through these FORMs and invoke system functionalities, posing significant risks to data integrity and availability.

Affected Version(s)

SAP NetWeaver Application Server ABAP and ABAP Platform SAP_BASIS 700

SAP NetWeaver Application Server ABAP and ABAP Platform SAP_BASIS 701

SAP NetWeaver Application Server ABAP and ABAP Platform SAP_BASIS 702

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.