CVE-2026-58246
Received Received - Intake

Sensitive Session ID Exposure in SAP NetWeaver ABAP Platform

Vulnerability report for CVE-2026-58246, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-28

Last updated on: 2026-07-28

Assigner: SAP SE

Description

SAP NetWeaver Application Server for ABAP and ABAP Platform writes sensitive session identifier information into a diagnostic trace when the trace is activated by a privileged user. An attacker with access to the resulting trace data could obtain identifiers that allow impersonation of legitimate users during their validity period.Β This leads to high impact on confidentiality. Integrity and availability are not impacted.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-28
Last Modified
2026-07-28
Generated
2026-07-28
AI Q&A
2026-07-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
sap netweaver_application_server_for_abap *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-497 The product does not properly prevent sensitive system-level information from being accessed by unauthorized actors who do not have the same level of access to the underlying system as the product does.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

SAP NetWeaver Application Server for ABAP and ABAP Platform logs sensitive session identifiers in diagnostic traces when activated by a privileged user. Attackers with access to these traces could steal session IDs and impersonate legitimate users during active sessions, compromising confidentiality.

Detection Guidance

This vulnerability involves sensitive session identifiers being written to diagnostic traces. To detect it, check SAP NetWeaver trace files for exposed session IDs or unusual trace activations by privileged users. Review trace configurations and logs for unauthorized trace activations or access to trace data.

Impact Analysis

If an attacker gains access to trace files containing session identifiers, they could impersonate legitimate users, leading to unauthorized access to sensitive data or systems. This primarily affects confidentiality of user sessions.

Compliance Impact

This vulnerability could lead to unauthorized access to personal or sensitive data, potentially violating GDPR (data protection) and HIPAA (health information privacy) requirements. Organizations must address this to maintain compliance.

Mitigation Strategies

Review and restrict access to diagnostic trace functionality for privileged users. Ensure trace data is securely stored and monitored for unauthorized access. Apply SAP Security Notes as recommended in SAP Security Patch Day resources.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-58246. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart