CVE-2026-58236
Received Received - Intake

OS Command Injection in SAP NetWeaver ABAP Platform

Vulnerability report for CVE-2026-58236, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-11

Last updated on: 2026-08-11

Assigner: SAP SE

Description

SAP NetWeaver Application Server ABAP and ABAP Platform allow an attacker with high privileges to bypass missing security controls on an internal code path leading to operating system command execution. Successful exploitation could allow the attacker to execute OS-level commands that write to the operating system or stop the SAP system, resulting in no impact on confidentiality, low impact on integrity, and high impact on availability.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-11
Last Modified
2026-08-11
Generated
2026-08-11
AI Q&A
2026-08-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
sap netweaver_application_server_abap *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-78 The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform allows an attacker with high privileges to bypass security controls and execute operating system commands. This could let them write to the OS or stop the SAP system, affecting system availability.

Impact Analysis

An attacker could disrupt SAP system operations by stopping services or modifying files, leading to downtime. Confidentiality is unaffected, integrity has low impact, but availability is highly compromised.

Compliance Impact

This vulnerability primarily impacts availability with high severity, which could lead to system outages or disruptions. For GDPR, availability issues may affect data access but not directly confidentiality or integrity. HIPAA focuses on integrity and availability, so high impact on availability could pose compliance risks if systems storing protected health information become unavailable.

Mitigation Strategies

Apply SAP security notes or patches addressing missing security controls in SAP NetWeaver Application Server ABAP. Restrict high-privilege user access to prevent unauthorized command execution. Monitor system logs for suspicious OS command activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-58236. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart