CVE-2026-58243
8.8SAP · SAP ABAP Developer Tools
SAP ABAP Developer Tools lacks authorization checks, allowing authenticated users with low privileges to execute unauthorized database operations against SAP NetWeaver AS ABAP.
Executive summary
A missing authorization vulnerability in SAP ABAP Developer Tools allows authenticated attackers to perform unauthorized database operations, posing a significant risk to data integrity and availability.
Vulnerability
This is a missing authorization vulnerability (CWE-862) occurring within SAP ABAP Developer Tools. It permits an attacker who has already authenticated with low privileges to bypass standard access controls and interact directly with database functions within SAP NetWeaver AS ABAP.
Business impact
Successful exploitation of this vulnerability allows unauthorized modification or deletion of sensitive business data, potentially leading to severe operational disruption. Given the CVSS score of 8.8, this flaw is considered High severity, as it facilitates unauthorized database manipulation that could compromise the confidentiality, integrity, and availability of core enterprise systems.
Remediation
Immediate Action: Apply the relevant security patches provided by SAP via the official SAP Security Note 3772411.
Proactive Monitoring: Review SAP system access logs for unusual database queries or unauthorized attempts to access administrative development functions by low-privileged user accounts.
Compensating Controls: Ensure that the principle of least privilege is strictly enforced for all user accounts, and restrict access to development tools to only those users who require them for their official duties.
Exploitation status
Public Exploit Available: No
Analyst recommendation
The vulnerability represents a significant security gap in the SAP environment that could be leveraged for destructive database operations. Security teams must prioritize applying the vendor-supplied patches to affected SAP_BASIS versions immediately to mitigate the risk of unauthorized system exploitation.