SAPCVE-2026-58246
SAP NetWeaver Application Server for ABAP: system information exposure
Medium4.3CVE-2026-58246 · Published Jul 28, 2026
SAP NetWeaver Application Server for ABAP and ABAP Platform writes sensitive session identifier information into a diagnostic trace when the trace is activated by a privileged user. An attacker with access to the resulting trace data could obtain identifiers that allow impersonation of legitimate users during their validity period. This leads to high impact on confidentiality. Integrity and availability are not impacted.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| SAP NetWeaver Application Server for ABAP Product | <= SAP_BASIS 740 | No fix yet |
| <= SAP_BASIS 750 | No fix yet | |
| <= SAP_BASIS 751 | No fix yet | |
| <= SAP_BASIS 752 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-497
More SAP advisories
All SAP| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 14 | SAP Commerce Cloud could retain a sample OAuth2 client with publicly documented... | Critical9.1 | No fix yet |
| Jul 14 | SAP @ui5/webcomponents-base: clickjacking | Medium6.1 | No fix yet |
| Jul 14 | SAP CRM (WebClient UI): attacker could inject | Medium4.1 | No fix yet |
| Jul 14 | SAP S/4HANA Project Management (PPM-PRO): SQL injection | Medium5.5 | No fix yet |
| Jul 14 | SAP S/4 HANA (Create Single Payment): missing authorization | Medium4.3 | No fix yet |
| Jul 14 | SAP S/4HANA (Draft operation): privilege escalation | Medium4.3 | No fix yet |