Session Identifier Exposure in SAP NetWeaver Application Server for ABAP
CVE-2026-58246

4.3MEDIUM

Key Information:

Vendor

SAP

Vendor
CVE Published:
28 July 2026

What is CVE-2026-58246?

The SAP NetWeaver Application Server for ABAP and ABAP Platform inadvertently exposes sensitive session identifier information in a diagnostic trace when activated by a privileged user. An attacker with access to this diagnostic trace can retrieve session identifiers, which may allow them to impersonate legitimate users, compromising user confidentiality during the session's validity period. This represents a significant risk for organizations using this product, necessitating immediate awareness and proactive measures to mitigate potential security breaches.

Affected Version(s)

SAP NetWeaver Application Server for ABAP ABAP SAP_BASIS 740

SAP NetWeaver Application Server for ABAP ABAP SAP_BASIS 750

SAP NetWeaver Application Server for ABAP ABAP SAP_BASIS 751

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.