Junglewise Threat Intelligence

CVE-2026-40135: SAP NetWeaver AS for ABAP OS command injection

CVE-2026-40135 · Severity: medium · CVSS 6.5 · Published 2026-05-12

Technologies: SAP NetWeaver Application Server for ABAP. Vendors: SAP.

Executive brief

SAP NetWeaver Application Server for ABAP is a foundational platform used by organizations to run business-critical SAP applications. A vulnerability exists that allows an administrative user to execute unauthorized operating system commands on the server. While this requires high-level access, an exploit could allow an attacker to disrupt business operations or modify system data without being detected by standard logging mechanisms.

Technical details

An OS command injection vulnerability (CWE-77) exists in SAP NetWeaver Application Server for ABAP and ABAP Platform. The flaw allows an authenticated attacker with high privileges (administrative access) to execute specially crafted shell commands on the underlying server via the network. A significant aspect of this vulnerability is the ability to bypass the system's logging mechanism, allowing for undetected execution of unintended commands. This can lead to a complete loss of integrity and availability for the affected application. SAP has released security notes (e.g., 3730019) to address this issue.

Affected products

  • SAP NetWeaver Application Server for ABAP 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 758, 816
  • SAP ABAP Platform

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory

References

Related threats