Code Injection Vulnerability in SAP Application Server ABAP for SAP NetWeaver
CVE-2026-40129
4.3MEDIUM
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 12 May 2026
What is CVE-2026-40129?
A vulnerability in the SAP Application Server ABAP for SAP NetWeaver and ABAP Platform allows authenticated attackers to exploit code injection. By sending specially crafted input to the application, an attacker could potentially execute arbitrary code affecting other users. This could compromise the integrity of the application while maintaining user confidentiality and system availability.
Affected Version(s)
SAP Application Server ABAP for SAP NetWeaver and ABAP Platform SAP_BASIS 740
SAP Application Server ABAP for SAP NetWeaver and ABAP Platform SAP_BASIS 750
SAP Application Server ABAP for SAP NetWeaver and ABAP Platform SAP_BASIS 751