me.sap.com
https://me.sap.com/notes/3745182 CVE-2026-58236
MEDIUM
OS Command Injection vulnerability in Application Server ABAP of SAP NetWeaver and ABAP Platform
Record summary
CVE-2026-58236 has a selected CVSS score of 5.5 (medium).
Description
SAP NetWeaver Application Server ABAP and ABAP Platform allow an attacker with high privileges to bypass missing security controls on an internal code path leading to operating system command execution. Successful exploitation could allow the attacker to execute OS-level commands that write to the operating system or stop the SAP system, resulting in no impact on confidentiality, low impact on integrity, and high impact on availability.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 11, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
SAP NetWeaver Application Server ABAP and ABAP PlatformBrowse SAP_SE / SAP NetWeaver Application Server ABAP and ABAP PlatformDefault status: unaffected | CVE List | KRNL64NUC 7.22 | affected |
| 7.22EXT | affected | ||
| KRNL64UC 7.22 | affected | ||
| 7.53 | affected | ||
| KERNEL 7.22 | affected | ||
| 7.54 | affected | ||
| 7.77 | affected | ||
| 7.93 | affected | ||
| 9.16 | affected |
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-58236 url.sap
https://url.sap/sapsecuritypatchday