Executive brief
SAP ABAP Development Tools, a component used by developers to build and modify SAP business applications, fails to properly validate user permissions before allowing database operations. An attacker with basic system access can bypass these checks to read confidential business data, modify application logic and records, and prevent legitimate users from accessing the system—impacting data security, system integrity, and business continuity.
Technical details
This is an authorization bypass vulnerability in SAP ABAP Development Tools affecting SAP NetWeaver AS ABAP. The vulnerability stems from missing authorization checks on certain database operation functionality, allowing low-privileged attackers to perform unauthorized actions. The attack vector is network-based with low privileges required; no additional user interaction is needed. Successful exploitation permits reading sensitive data, modifying application data, and disrupting availability. A patch is available through SAP Security Patch Day (published August 11, 2026).
Affected products
- SAP NetWeaver AS ABAP <UNKNOWN>
- SAP ABAP Development Tools <UNKNOWN>
Timeline
- 2026-08-11: disclosed