Junglewise Threat Intelligence

CVE-2026-58236: SAP NetWeaver Application Server ABAP OS command execution via security control bypass

CVE-2026-58236 · Severity: medium · CVSS 5.5 · Published 2026-08-11

Technologies: SAP NetWeaver Application Server ABAP. Vendors: SAP.

Executive brief

SAP NetWeaver Application Server ABAP and ABAP Platform are enterprise middleware systems used to run critical business applications and processes. A high-privilege attacker can bypass security controls to execute operating system commands, potentially stopping the system or corrupting data. This could cause significant business disruption and system downtime.

Technical details

This vulnerability involves a missing security control on an internal code path in SAP NetWeaver Application Server ABAP and ABAP Platform that allows OS command execution. The attack requires high-level privileges, indicating the threat actor must already have elevated access to the system. Successful exploitation enables execution of arbitrary OS-level commands, leading to high impact on availability (system shutdown) and low impact on integrity (file modification). The CVSS 5.5 (medium) score reflects the requirement for high privileges as a precondition. Patches are available via SAP Security Notes published on the regular SAP Security Patch Day schedule.

Affected products

  • SAP NetWeaver Application Server ABAP <UNKNOWN>
  • SAP ABAP Platform <UNKNOWN>

Timeline

  • 2026-08-11: disclosed

References

Related threats