SAP NetWeaver Application Server ABAP Vulnerability Allowing Unauthorized Remote Function Calls
CVE-2026-0509
9.6CRITICAL
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 10 February 2026
What is CVE-2026-0509?
A security flaw in the SAP NetWeaver Application Server ABAP and ABAP Platform permits an authenticated, low-privileged user to execute background Remote Function Calls without the necessary S_RFC authorization under certain circumstances. This oversight may lead to significant impacts on the integrity and availability of the systems involved, while the confidentiality of the application remains unaffected.
Affected Version(s)
SAP NetWeaver Application Server ABAP and ABAP Platform KRNL64NUC 7.22
SAP NetWeaver Application Server ABAP and ABAP Platform 7.22EXT
SAP NetWeaver Application Server ABAP and ABAP Platform KRNL64UC 7.22