CVE-2026-0488

CRITICAL

SAP CRM/S/4HANA - Privilege Escalation

Title source: llm
STIX 2.1

Description

An authenticated attacker in SAP CRM and SAP S/4HANA (Scripting Editor) could exploit a flaw in a generic function module call and execute unauthorized critical functionalities, which includes the ability to execute an arbitrary SQL statement. This leads to a full database compromise with high impact on confidentiality, integrity, and availability.

References (2)

Core 2
Core References
Permissions Required
https://me.sap.com/notes/3697099

Scores

CVSS v3 9.9
EPSS 0.0002
EPSS Percentile 6.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-862
Status published
Products (18)
sap/netweaver_application_server_abap 700
sap/s\/4hana 102
sap/s\/4hana 103
sap/s\/4hana 104
sap/s\/4hana 105
sap/s\/4hana 106
sap/s\/4hana 107
sap/s\/4hana 108
sap/s\/4hana 109
sap/webclient_ui_framework 700
... and 8 more
Published Feb 10, 2026
Tracked Since Feb 18, 2026