SAPCVE-2026-58236
SAP NetWeaver Application Server ABAP and ABAP Platform: command injection
Medium5.5CVE-2026-58236 · Published Aug 11, 2026 · updated Aug 26, 2026
SAP NetWeaver Application Server ABAP and ABAP Platform allow an attacker with high privileges to bypass missing security controls on an internal code path leading to operating system command execution. Successful exploitation could allow the attacker to execute OS-level commands that write to the operating system or stop the SAP system, resulting in no impact on confidentiality, low impact on integrity, and high impact on availability.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| SAP NetWeaver Application Server ABAP and ABAP Platform Product | <= KRNL64NUC 7.22 | No fix yet |
| <= 7.22EXT | No fix yet | |
| <= KRNL64UC 7.22 | No fix yet | |
| <= 7.53 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-78
More SAP advisories
All SAP| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 11 | SAP Commerce Cloud (Data Hub Adapter): remote code execution | Critical10.0 | No fix yet |
| Aug 11 | SAP Business AI Platform (Approuter): improper signature check | Medium5.9 | No fix yet |
| Aug 11 | SAP Business AI Platform (Approuter): path traversal | Medium5.9 | No fix yet |
| Aug 11 | SAP Approuter does not sufficiently sanitize certain request headers before... | Medium5.3 | No fix yet |
| Aug 11 | SAP NetWeaver Application Server ABAP: cross-site scripting | Medium6.3 | No fix yet |
| Aug 11 | SAP BusinessObjects Business Intelligence Platform (Central : hard-coded key | High7.9 | No fix yet |