Description
An OS Command Injection vulnerability exists in the SAP NetWeaver Application Server for ABAP and ABAP Platform that allows an authenticated attacker with administrative access to execute specially crafted shell commands on the server, bypassing the logging mechanism. This allows the execution of unintended OS commands without detection, potentially impacting the integrity and availability of the application, with no impact on confidentiality.
Published: 2026-05-12
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability identified as OS Command Injection allows an authenticated attacker with administrative privileges to run arbitrary shell commands on the SAP NetWeaver Application Server for ABAP and ABAP Platform. This flaw bypasses the system’s logging mechanism, enabling the execution of unintended OS commands without detection. The impact is primarily on integrity and availability, as malicious code can alter system state or disrupt services, while confidentiality remains unaffected. The weakness is classified as CWE‑77.

Affected Systems

All versions of SAP NetWeaver Application Server for ABAP and ABAP Platform that are covered by this vulnerability are impacted, although specific affected releases are not listed in the advisory. Administrators should check the SAP Note 3730019 for the exact editions and build numbers that require remediation.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity, and the lack of an EPSS value means the exploit probability is not publicly quantified. The vulnerability is not recorded in CISA’s KEV catalogue. Given that the attack requires authenticated administrative access, the risk is elevated for environments where such credentials are widely available or poorly protected. Because the logger is bypassed, malicious activity may go unnoticed, increasing potential damage before detection.

Generated by OpenCVE AI on May 12, 2026 at 04:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the security patch released in SAP Note 3730019 to address the command injection flaw.
  • Restrict administrative access to the SAP NetWeaver Application Server for ABAP to the minimum number of privileged users.
  • Enable comprehensive audit logging for command execution and regularly review logs for anomalous activity.

Generated by OpenCVE AI on May 12, 2026 at 04:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 12 May 2026 13:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 12 May 2026 09:15:00 +0000

Type Values Removed Values Added
First Time appeared Sap Se
Sap Se sap Netweaver Application Server Abap And Abap Platform
Vendors & Products Sap Se
Sap Se sap Netweaver Application Server Abap And Abap Platform

Tue, 12 May 2026 03:00:00 +0000

Type Values Removed Values Added
Description An OS Command Injection vulnerability exists in the SAP NetWeaver Application Server for ABAP and ABAP Platform that allows an authenticated attacker with administrative access to execute specially crafted shell commands on the server, bypassing the logging mechanism. This allows the execution of unintended OS commands without detection, potentially impacting the integrity and availability of the application, with no impact on confidentiality.
Title OS Command Injection vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform
Weaknesses CWE-77
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H'}


Subscriptions

Sap Se Sap Netweaver Application Server Abap And Abap Platform
cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published:

Updated: 2026-05-12T13:03:50.003Z

Reserved: 2026-04-09T17:29:44.663Z

Link: CVE-2026-40135

cve-icon Vulnrichment

Updated: 2026-05-12T13:03:46.426Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-05-12T03:16:12.430

Modified: 2026-05-12T14:19:41.400

Link: CVE-2026-40135

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-12T09:00:06Z

Weaknesses