Authorization Bypass in SAP ABAP Development Tools Allowing Unauthorized Database Operations
CVE-2026-58243

8.8HIGH

Key Information:

Vendor

SAP

Vendor
CVE Published:
11 August 2026

What is CVE-2026-58243?

SAP ABAP Development Tools contains a flaw that fails to enforce adequate authorization controls for specific functionalities. This vulnerability permits low-privileged attackers to execute unauthorized database operations on SAP NetWeaver AS ABAP. If successfully exploited, this could lead to unauthorized access to sensitive information, modification of application data, and potential disruption for legitimate users, thereby undermining the overall security and operational integrity of the system.

Affected Version(s)

SAP ABAP Developer Tools SAP_BASIS 750

SAP ABAP Developer Tools SAP_BASIS 751

SAP ABAP Developer Tools SAP_BASIS 752

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.