CVE-2026-0500

CRITICAL

SAP Wily Introscope Enterprise Manager - Unauthenticated OS Command Injection via Malicious JNLP File

Title source: llm
STIX 2.1

Description

Due to the usage of vulnerable third party component in SAP Wily Introscope Enterprise Manager (WorkStation), an unauthenticated attacker could create a malicious JNLP (Java Network Launch Protocol) file accessible by a public facing URL. When a victim clicks on the URL the accessed Wily Introscope Server could execute OS commands on the victim's machine. This could completely compromising confidentiality, integrity and availability of the system.

References (2)

Core 2
Core References
Permissions Required
https://me.sap.com/notes/3668679
Patch, Vendor Advisory
https://url.sap/sapsecuritypatchday

Scores

CVSS v3 9.6
EPSS 0.0017
EPSS Percentile 38.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-94
Status published
Products (1)
sap/introscope_enterprise_manager 10.8
Published Jan 13, 2026
Tracked Since Feb 18, 2026