CVE-2026-58236

Summary

SAP NetWeaver Application Server ABAP and ABAP Platform allow an attacker with high privileges to bypass missing security controls on an internal code path leading to operating system command execution. Successful exploitation could allow the attacker to execute OS-level commands that write to the operating system or stop the SAP system, resulting in no impact on confidentiality, low impact on integrity, and high impact on availability.

Affected Software

VendorProductVersion RangeStatus
SAP_SESAP NetWeaver Application Server ABAP and ABAP PlatformKRNL64NUC 7.22affected
SAP_SESAP NetWeaver Application Server ABAP and ABAP Platform7.22EXTaffected
SAP_SESAP NetWeaver Application Server ABAP and ABAP PlatformKRNL64UC 7.22affected
SAP_SESAP NetWeaver Application Server ABAP and ABAP Platform7.53affected
SAP_SESAP NetWeaver Application Server ABAP and ABAP PlatformKERNEL 7.22affected
SAP_SESAP NetWeaver Application Server ABAP and ABAP Platform7.54affected
SAP_SESAP NetWeaver Application Server ABAP and ABAP Platform7.77affected
SAP_SESAP NetWeaver Application Server ABAP and ABAP Platform7.93affected
SAP_SESAP NetWeaver Application Server ABAP and ABAP Platform9.16affected

Weaknesses

  • CWE-78: CWE-78: Improper Neutralization of Special Elements used in an OS Command

References