Description
SAP NetWeaver Application Server ABAP and ABAP Platform allow an attacker with high privileges to bypass missing security controls on an internal code path leading to operating system command execution. Successful exploitation could allow the attacker to execute OS-level commands that write to the operating system or stop the SAP system, resulting in no impact on confidentiality, low impact on integrity, and high impact on availability.
Published: 2026-08-11
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An internal code path in SAP NetWeaver Application Server ABAP and ABAP Platform can be abused by an attacker with high system privileges to trigger an operating‑system command injection. The flaw allows the attacker to run arbitrary OS commands that can write data to the file system or shut down the SAP instance. The vulnerability does not compromise data confidentiality, has a low potential to alter system state, but can cause a loss of service because it can stop or destabilize the SAP environment.

Affected Systems

Products affected are SAP NetWeaver Application Server ABAP and the ABAP platform. Specific version details are not disclosed in the CVE data, so any instance of these products that has not applied the SAP security fix remains vulnerable.

Risk and Exploitability

The CVSS base score of 5.5 indicates a medium severity, and the lack of an EPSS score means no current estimation of exploitation probability is available. The vulnerability is not listed in the CISA KEV catalog. Inferred from the description, the exploitation path requires privileged access, so the risk is confined to internally empowered users. Successful exploitation could allow an attacker to execute OS-level commands that write to the operating system or stop the SAP system, resulting in no impact on confidentiality, low impact on integrity, and high impact on availability.

Generated by OpenCVE AI on August 11, 2026 at 01:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the SAP security note 3745182 to install the patch that fixes the command injection path.
  • Deploy the patch according to SAP’s Rapid Security Patch Day procedures or the official release notes, ensuring the fix is installed on all affected Application Server ABAP and ABAP Platform instances.
  • Restrict the privilege level of users who can access the affected internal code path, and monitor for any unauthorized attempts to execute system commands.

Generated by OpenCVE AI on August 11, 2026 at 01:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 11 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 02:30:00 +0000

Type Values Removed Values Added
First Time appeared Sap Se
Sap Se sap Netweaver Application Server Abap And Abap Platform
Vendors & Products Sap Se
Sap Se sap Netweaver Application Server Abap And Abap Platform

Tue, 11 Aug 2026 00:45:00 +0000

Type Values Removed Values Added
Description SAP NetWeaver Application Server ABAP and ABAP Platform allow an attacker with high privileges to bypass missing security controls on an internal code path leading to operating system command execution. Successful exploitation could allow the attacker to execute OS-level commands that write to the operating system or stop the SAP system, resulting in no impact on confidentiality, low impact on integrity, and high impact on availability.
Title OS Command Injection vulnerability in Application Server ABAP of SAP NetWeaver and ABAP Platform
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H'}


Subscriptions

Sap Se Sap Netweaver Application Server Abap And Abap Platform
cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published:

Updated: 2026-08-11T14:31:47.209Z

Reserved: 2026-06-29T19:34:28.222Z

Link: CVE-2026-58236

cve-icon Vulnrichment

Updated: 2026-08-11T14:31:42.738Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-11T01:17:21.553

Modified: 2026-08-26T19:00:14.450

Link: CVE-2026-58236

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-11T02:15:03Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')