8.1

CVE-2026-0506

Medienbericht
Due to a Missing Authorization Check vulnerability in Application Server ABAP and ABAP Platform, an authenticated attacker could misuse an RFC function to execute form routines (FORMs) in the ABAP system. Successful exploitation could allow the attacker to write or modify data accessible via FORMs and invoke system functionality exposed via FORMs, resulting in a high impact on integrity and availability, while confidentiality remains unaffected.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SAPNetweaver Application Server Abap Version700 SwEditionsap_basis
SAPNetweaver Application Server Abap Version701 SwEditionsap_basis
SAPNetweaver Application Server Abap Version702 SwEditionsap_basis
SAPNetweaver Application Server Abap Version731 SwEditionsap_basis
SAPNetweaver Application Server Abap Version740 SwEditionsap_basis
SAPNetweaver Application Server Abap Version750 SwEditionsap_basis
SAPNetweaver Application Server Abap Version751 SwEditionsap_basis
SAPNetweaver Application Server Abap Version752 SwEditionsap_basis
SAPNetweaver Application Server Abap Version753 SwEditionsap_basis
SAPNetweaver Application Server Abap Version754 SwEditionsap_basis
SAPNetweaver Application Server Abap Version755 SwEditionsap_basis
SAPNetweaver Application Server Abap Version756 SwEditionsap_basis
SAPNetweaver Application Server Abap Version757 SwEditionsap_basis
SAPNetweaver Application Server Abap Version758 SwEditionsap_basis
SAPNetweaver Application Server Abap Version816 SwEditionsap_basis
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.04% 0.131
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
cna@sap.com 8.1 2.8 5.2
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
CWE-862 Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.