Record summary

CVE-2026-58236 has a selected CVSS score of 5.5 (medium).

Description

SAP NetWeaver Application Server ABAP and ABAP Platform allow an attacker with high privileges to bypass missing security controls on an internal code path leading to operating system command execution. Successful exploitation could allow the attacker to execute OS-level commands that write to the operating system or stop the SAP system, resulting in no impact on confidentiality, low impact on integrity, and high impact on availability.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 11, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

SAP NetWeaver Application Server ABAP and ABAP Platform

Browse SAP_SE / SAP NetWeaver Application Server ABAP and ABAP Platform

Default status: unaffected

CVE ListKRNL64NUC 7.22affected
7.22EXTaffected
KRNL64UC 7.22affected
7.53affected
KERNEL 7.22affected
7.54affected
7.77affected
7.93affected
9.16affected

References

3