Description
SAP NetWeaver Application Server ABAP and ABAP Platform allow an attacker with high privileges to bypass missing security controls on an internal code path leading to operating system command execution. Successful exploitation could allow the attacker to execute OS-level commands that write to the operating system or stop the SAP system, resulting in no impact on confidentiality, low impact on integrity, and high impact on availability.
Published: 2026-08-11
Score: 5.5 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An internal code path in SAP NetWeaver Application Server ABAP and ABAP Platform can be abused by an attacker with high system privileges to trigger an operating‑system command injection. The flaw allows the attacker to run arbitrary OS commands that can write data to the file system or shut down the SAP instance. The vulnerability does not compromise data confidentiality, has a low potential to alter system state, but can cause a loss of service because it can stop or destabilize the SAP environment.

Affected Systems

Products affected are SAP NetWeaver Application Server ABAP and the ABAP platform. Specific version details are not disclosed in the CVE data, so any instance of these products that has not applied the SAP security fix remains vulnerable.

Risk and Exploitability

The CVSS base score of 5.5 indicates a medium severity, and the lack of an EPSS score means no current estimation of exploitation probability is available. The vulnerability is not listed in the CISA KEV catalog. Inferred from the description, the exploitation path requires privileged access, so the risk is confined to internally empowered users. Successful exploitation could allow an attacker to execute OS-level commands that write to the operating system or stop the SAP system, resulting in no impact on confidentiality, low impact on integrity, and high impact on availability.

Generated by OpenCVE AI on August 11, 2026 at 01:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the SAP security note 3745182 to install the patch that fixes the command injection path.
  • Deploy the patch according to SAP’s Rapid Security Patch Day procedures or the official release notes, ensuring the fix is installed on all affected Application Server ABAP and ABAP Platform instances.
  • Restrict the privilege level of users who can access the affected internal code path, and monitor for any unauthorized attempts to execute system commands.

Generated by OpenCVE AI on August 11, 2026 at 01:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 11 Aug 2026 00:45:00 +0000

Type Values Removed Values Added
Description SAP NetWeaver Application Server ABAP and ABAP Platform allow an attacker with high privileges to bypass missing security controls on an internal code path leading to operating system command execution. Successful exploitation could allow the attacker to execute OS-level commands that write to the operating system or stop the SAP system, resulting in no impact on confidentiality, low impact on integrity, and high impact on availability.
Title OS Command Injection vulnerability in Application Server ABAP of SAP NetWeaver and ABAP Platform
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published:

Updated: 2026-08-11T00:12:40.625Z

Reserved: 2026-06-29T19:34:28.222Z

Link: CVE-2026-58236

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-11T01:30:04Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')