Command Execution Vulnerability in SAP NetWeaver Application Server ABAP
CVE-2026-58236

5.5MEDIUM

What is CVE-2026-58236?

The SAP NetWeaver Application Server ABAP and ABAP Platform are exposed to a vulnerability that allows attackers with elevated privileges to exploit missing security controls. This vulnerability facilitates the execution of operating system commands via an internal code path. An attacker could leverage this flaw to execute OS-level commands that can modify the operating system or halt the SAP system entirely, which can lead to significant availability issues. Organizations using affected versions should apply recommended patches promptly to mitigate risks.

Affected Version(s)

SAP NetWeaver Application Server ABAP and ABAP Platform KRNL64NUC 7.22

SAP NetWeaver Application Server ABAP and ABAP Platform 7.22EXT

SAP NetWeaver Application Server ABAP and ABAP Platform KRNL64UC 7.22

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.