CVE-2026-27671
Awaiting Analysis Awaiting Analysis - Queue
Memory Corruption in SAP NetWeaver ABAP Platform

Publication date: 2026-06-09

Last updated on: 2026-06-09

Assigner: SAP SE

Description
Due to improper RFC protocol validation in the SAP Kernel used by the Application Server ABAP of SAP NetWeaver and ABAP Platform, an unauthenticated attacker can send a crafted RFC request that exploits logical errors in memory management, leading to memory corruption. This could lead to a high impact on the confidentiality, integrity, and availability of the application.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-09
Last Modified
2026-06-09
Generated
2026-06-09
AI Q&A
2026-06-09
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
sap sap_kernel *
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-121 A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability arises from improper RFC protocol validation in the SAP Kernel used by the Application Server ABAP of SAP NetWeaver and ABAP Platform. An unauthenticated attacker can send a specially crafted RFC request that exploits logical errors in memory management, which leads to memory corruption.

Impact Analysis

The vulnerability can have a high impact on the confidentiality, integrity, and availability of the affected application. This means that an attacker could potentially access sensitive information, alter data, or disrupt the normal operation of the application.

Compliance Impact

This vulnerability in the SAP Kernel can lead to memory corruption that impacts the confidentiality, integrity, and availability of the application. Such impacts on data security and system reliability could potentially affect compliance with common standards and regulations like GDPR and HIPAA, which require protection of sensitive data and system integrity.

However, the provided information does not explicitly describe how this vulnerability affects compliance with these standards or regulations.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-27671. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart