CVE-2026-40135

MEDIUM WAF: High
CVSS 6.5 Published: 2026-05-12
CWE-77

An OS Command Injection vulnerability exists in the SAP NetWeaver Application Server for ABAP and ABAP Platform that allows an authenticated attacker with administrative access to execute specially crafted shell commands on the server, bypassing the logging mechanism. This allows the execution of unintended OS commands without detection, potentially impacting the integrity and availability of the application, with no impact on confidentiality.

WAF Coverage Analysis

Command Injection High WAF Coverage

OWASP: A03:2021 Injection

932xxx - Remote Code Execution

Affected Software

VendorProductVersion
sapnetweaver_application_server_abap700
sapnetweaver_application_server_abap701
sapnetweaver_application_server_abap702
sapnetweaver_application_server_abap731
sapnetweaver_application_server_abap740
sapnetweaver_application_server_abap750
sapnetweaver_application_server_abap751
sapnetweaver_application_server_abap752
sapnetweaver_application_server_abap753
sapnetweaver_application_server_abap754

References

Back to CVE Database