CVE-2026-0506

8.1

SAP · NetWeaver Application Server ABAP and ABAP Platform

A missing authorization check in SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated attacker to execute arbitrary form routines via RFC functions.

Executive summary

A missing authorization vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform allows authenticated attackers to manipulate system data and invoke unauthorized functionality.

Vulnerability

The vulnerability involves a missing authorization check (CWE-862) within the RFC function handling, which allows an authenticated attacker to execute form routines (FORMs). This flaw permits the execution of system functions and data modifications that should otherwise be restricted to authorized users.

Business impact

The exploitation of this vulnerability poses a significant risk to the integrity and availability of SAP business systems. Because the attacker can modify data and invoke system functions, business operations could be disrupted or critical records tampered with. With a CVSS score of 8.1, the high impact on integrity and availability necessitates prompt remediation to prevent unauthorized system manipulation.

Remediation

Immediate Action: Review the official SAP Security Note 3688703 and apply the corresponding patches to the affected SAP_BASIS components.

Proactive Monitoring: Monitor RFC traffic logs for suspicious calls to unknown or sensitive form routines and audit changes to system configurations.

Compensating Controls: Ensure that access to RFC-enabled functions is strictly limited to authenticated users with the minimum required privileges, and apply network-level segmentation to restrict access to the application server.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the high CVSS score and the potential for unauthorized data modification, organizations running the affected SAP_BASIS versions must prioritize the application of vendor patches. Please consult the SAP support portal to verify your specific build and apply the necessary security updates to mitigate the risk of unauthorized administrative-level actions within the ABAP environment.

More SAP CVEs

Sources