CVE-2026-0509
CRITICAL WAF: Low
CVSS 9.6
Published: 2026-02-10
CWE-862
SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated, low-privileged user to perform background Remote Function Calls without the required S_RFC authorization in certain cases. This can result in a high impact on integrity and availability, and no impact on the confidentiality of the application.
WAF Coverage Analysis
Missing Authorization
Low WAF Coverage
OWASP: A01:2021 Broken Access Control
Affected Software
| Vendor | Product | Version |
|---|---|---|
| sap | netweaver_as_abap_kernel | 7.22 |
| sap | netweaver_as_abap_kernel | 7.53 |
| sap | netweaver_as_abap_kernel | 7.54 |
| sap | netweaver_as_abap_kernel | 7.77 |
| sap | netweaver_as_abap_kernel | 7.89 |
| sap | netweaver_as_abap_kernel | 7.93 |
| sap | netweaver_as_abap_kernel | 9.16 |
| sap | netweaver_as_abap_kernel | 9.18 |
| sap | netweaver_as_abap_kernel | 9.19 |
| sap | netweaver_as_abap_krnl64nuc | 7.22 |
References
- me.sap.com (Permissions Required)
- url.sap (Vendor Advisory)