Skip to content
SAPCVE-2026-58241

SAP NetWeaver and ABAP: missing authorization

Medium4.2CVE-2026-58241 · Published Aug 11, 2026 · updated Aug 26, 2026

SAP NetWeaver and ABAP Platform (Change and Transport System - Customer Transport Integration Wizard) allows a low-privileged user to modify configuration tables that control access to data objects during specific operations. These unauthorized modifications could result in processing delays and operational disruption, leading to a low impact on the integrity and availability of the application with no impact on confidentiality.

SAP advisory

Affected versions

PackageAffectedFixed in
SAP NetWeaver and ABAP Platform (Change and Transport System - Customer Transport Integration Wizard
Product
<= SAP_BASIS 740No fix yet
<= SAP_BASIS 750No fix yet
<= SAP_BASIS 751No fix yet
<= SAP_BASIS 752No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-862

More SAP advisories

All SAP
Advisory
SAP Commerce Cloud (Data Hub Adapter): remote code execution
Critical10.0Aug 11
SAP Business AI Platform (Approuter): improper signature check
Medium5.9Aug 11
SAP Business AI Platform (Approuter): path traversal
Medium5.9Aug 11
SAP Approuter does not sufficiently sanitize certain request headers before...
Medium5.3Aug 11
SAP NetWeaver Application Server ABAP: cross-site scripting
Medium6.3Aug 11
SAP BusinessObjects Business Intelligence Platform (Central : hard-coded key
High7.9Aug 11

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.