CVE-2026-58233
Awaiting Analysis Awaiting Analysis - Queue

Authenticated Insecure Deserialization in SAP Change and Transport System Attach Tool

Vulnerability report for CVE-2026-58233, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-14

Last updated on: 2026-07-14

Assigner: SAP SE

Description

SAP Change and Transport System Attach Tool (ctsattach) allows an authenticated attacker to supply a specially crafted archive file which, when processed by the application�s library, can trigger insecure deserialization and lead to remote code execution (RCE) on the system. Successful exploitation requires a victim to process the malicious archive, enabling the attacker to execute the RCE and extract sensitive information and gain control over the system and its processes. This vulnerability has a high impact on confidentiality and integrity of the data, with a low impact on the availability of the system.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-14
Last Modified
2026-07-14
Generated
2026-08-03
AI Q&A
2026-07-14
EPSS Evaluated
2026-08-02
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
sap change_and_transport_system_attach_tool 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-502 The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the SAP Change and Transport System Attach Tool (ctsattach). An authenticated attacker can create a specially crafted archive file that, when processed by the application's library, triggers insecure deserialization. This leads to remote code execution (RCE) on the system.

For the exploit to succeed, a victim must process the malicious archive. Once exploited, the attacker can execute arbitrary code, extract sensitive information, and gain control over the system and its processes.

The vulnerability has a high impact on confidentiality and integrity of the data but a low impact on the availability of the system.

Detection Guidance

Detecting this vulnerability on your network or system involves checking for the presence of the SAP Change and Transport System Attach Tool (ctsattach) and monitoring for suspicious archive file processing. Since the vulnerability is triggered by processing a specially crafted archive file, you can look for unusual or unexpected archive files being processed by the application.

  • Check installed SAP components: Verify if the SAP Change and Transport System Attach Tool (ctsattach) is installed on your systems. This can typically be done via SAP transaction codes or by reviewing installed software lists.
  • Monitor file processing: Use system monitoring tools to track the processing of archive files by the ctsattach tool. Look for unexpected or unauthorized archive files being processed.
  • Review logs: Examine SAP system logs and application logs for any signs of deserialization errors or unusual activity related to archive file processing.
  • Network traffic analysis: Monitor network traffic for unusual outbound connections that might indicate remote code execution or data exfiltration.

Specific commands or tools for detection may depend on your SAP environment and the operating system in use. SAP provides guidance on security monitoring and logging in their security notes and documentation.

Impact Analysis

If you are using the SAP Change and Transport System Attach Tool (ctsattach), this vulnerability could have the following impacts:

  • An attacker could execute remote code on your system, allowing them to take control of it.
  • Sensitive information stored or processed by the system could be extracted or compromised.
  • The integrity of your data could be violated, as the attacker may modify or delete critical information.
  • While the system's availability is less likely to be severely impacted, there may still be disruptions depending on the attacker's actions.
Compliance Impact

This vulnerability can have significant implications for compliance with standards and regulations such as GDPR and HIPAA:

  • GDPR: The vulnerability's high impact on confidentiality and integrity could lead to unauthorized access or exposure of personal data. This may result in violations of GDPR's data protection requirements, potentially leading to fines or legal consequences.
  • HIPAA: If the affected system processes or stores protected health information (PHI), the vulnerability could lead to unauthorized access or disclosure of PHI. This would violate HIPAA's Privacy and Security Rules, potentially resulting in penalties.

Organizations must address this vulnerability promptly to avoid non-compliance and mitigate risks to sensitive data.

Mitigation Strategies

To mitigate this vulnerability, follow these immediate steps:

  • Apply SAP security patches: Check for and apply the latest security patches provided by SAP for the Change and Transport System Attach Tool (ctsattach). SAP Security Notes often include fixes for such vulnerabilities.
  • Restrict access: Limit access to the ctsattach tool to only authorized personnel. Ensure that only trusted users can process archive files using this tool.
  • Validate input files: Implement strict validation for any archive files processed by the ctsattach tool. Reject files that do not meet expected criteria or come from untrusted sources.
  • Monitor for exploitation attempts: Increase monitoring for signs of exploitation, such as unusual deserialization errors or unexpected system behavior.
  • Review SAP Security Notes: Refer to SAP Security Notes for specific guidance on mitigating this vulnerability. SAP may provide additional steps or workarounds in their official documentation.

For detailed patching instructions and further mitigation steps, consult the SAP Security Notes referenced in Resource 1 and Resource 2.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-58233. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart