Junglewise Threat Intelligence

CVE-2026-58233: SAP Change and Transport System Attach Tool insecure deserialization

CVE-2026-58233 · Severity: high · CVSS 7.6 · Published 2026-07-14

Vendors: SAP SE.

Executive brief

SAP Change and Transport System Attach Tool (ctsattach) is used to manage and move software changes across different SAP systems. A vulnerability in this tool allows an attacker to provide a malicious archive file that, if processed by a user, allows the attacker to take control of the system. This could lead to the theft of sensitive business data and disruption of system integrity, though it is less likely to cause a total service outage.

Technical details

An insecure deserialization vulnerability (CWE-502) exists in the SAP Change and Transport System Attach Tool (ctsattach) library. An authenticated attacker with network access can supply a specially crafted archive file to the application. If a victim processes this malicious archive, the application's library fails to safely deserialize the data, allowing the attacker to execute arbitrary code on the underlying system. This can result in full compromise of confidentiality and integrity, though it requires user interaction to trigger the processing of the archive. SAP has released Security Note 3773304 to address this issue.

Affected products

  • SAP SE Change and Transport System Attach Tool (ctsattach) CTS_UPLOAD_CLT 1

Timeline

  • 2026-07-14: advisory: Published as part of SAP July 2026 Security Patch Day
  • 2026-07-13: disclosed: NVD publication date

References