CVE-2026-24309

MEDIUM

SAP NetWeaver ABAP - Privilege Escalation

Title source: llm
STIX 2.1

Description

Due to missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker could execute specific ABAP function module to read, modify or insert entries into the database configuration table of the ABAP system. This unauthorized content change could lead to reduced system performance or interruptions. The vulnerability has low impact on the application's integrity and availability, with no effect on confidentiality.

References (2)

Core 2
Core References

Scores

CVSS v3 6.4
EPSS 0.0021
EPSS Percentile 10.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-862
Status published
Products (15)
sap/netweaver_application_server_abap 700
sap/netweaver_application_server_abap 701
sap/netweaver_application_server_abap 702
sap/netweaver_application_server_abap 731
sap/netweaver_application_server_abap 740
sap/netweaver_application_server_abap 750
sap/netweaver_application_server_abap 751
sap/netweaver_application_server_abap 752
sap/netweaver_application_server_abap 753
sap/netweaver_application_server_abap 754
... and 5 more
Published Mar 10, 2026
Tracked Since Mar 11, 2026