Description
SAP ABAP Development Tools does not perform necessary authorization checks for certain functionality, allowing an attacker with low privileges to execute unauthorized database operations against SAP NetWeaver AS ABAP. Successful exploitation could allow the attacker to read sensitive data, modify application data, and disrupt access for legitimate users, resulting in high impact on confidentiality, integrity, and availability.
Published: 2026-08-11
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

SAP ABAP Development Tools lacks necessary authorization checks for certain functions, allowing a user with low privileges to perform unauthorized database operations on SAP NetWeaver AS ABAP. This flaw can enable the attacker to read confidential data, modify application data, and disrupt service for legitimate users, impacting confidentiality, integrity, and availability. The weakness is classified as CWE-862, an authorization issue.

Affected Systems

The vulnerability applies to SAP SE’s SAP ABAP Developer Tools, which is part of the SAP NetWeaver AS ABAP environment. No specific version information is provided, so all installations of SAP ABAP Developer Tools that expose the affected functionality are potentially impacted.

Risk and Exploitability

The CVSS score of 8.8 indicates high severity. The EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog, suggesting no confirmed exploitation yet. The likely attack vector is local: an attacker must first obtain a low‑privilege account on the system and then use the developer tools to trigger the unchecked database operations. Because low‑privilege access is relatively easy to acquire through social engineering or existing permissions, the risk of successful exploitation remains significant.

Generated by OpenCVE AI on August 11, 2026 at 01:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the SAP security patch referenced in SAP Note 3772411 or upgrade to the latest SAP ABAP Developer Tools release that includes the fix.
  • Restrict or disable the functionality in ABAP Developer Tools that allows database operations for users with low privileges, ensuring that only authorized accounts can perform such actions.
  • Review and tighten access controls and monitor privileged and low‑privilege user activity within SAP NetWeaver AS ABAP to detect and prevent potential abuse.

Generated by OpenCVE AI on August 11, 2026 at 01:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 11 Aug 2026 00:45:00 +0000

Type Values Removed Values Added
Description SAP ABAP Development Tools does not perform necessary authorization checks for certain functionality, allowing an attacker with low privileges to execute unauthorized database operations against SAP NetWeaver AS ABAP. Successful exploitation could allow the attacker to read sensitive data, modify application data, and disrupt access for legitimate users, resulting in high impact on confidentiality, integrity, and availability.
Title Privilege Escalation vulnerability in SAP ABAP Developer Tools
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published:

Updated: 2026-08-11T00:16:07.468Z

Reserved: 2026-06-29T19:35:04.185Z

Link: CVE-2026-58243

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-11T01:30:04Z

Weaknesses