Configuration Access Vulnerability in SAP NetWeaver and ABAP Platform
CVE-2026-58241

4.2MEDIUM

What is CVE-2026-58241?

The SAP NetWeaver and ABAP Platform's Change and Transport System, specifically the Customer Transport Integration Wizard, has a vulnerability that allows low-privileged users to alter critical configuration tables governing access to key data objects. These unauthorized changes may lead to processing delays and operational disruptions, affecting the application’s overall performance and integrity without compromising the confidentiality of the data. Organizations using these versions should be aware of the risks and take appropriate measures to secure their configurations.

Affected Version(s)

SAP NetWeaver and ABAP Platform (Change and Transport System - Customer Transport Integration Wizard SAP_BASIS 740

SAP NetWeaver and ABAP Platform (Change and Transport System - Customer Transport Integration Wizard SAP_BASIS 750

SAP NetWeaver and ABAP Platform (Change and Transport System - Customer Transport Integration Wizard SAP_BASIS 751

References

CVSS V3.1

Score:
4.2
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.