CVE-2026-0509
EUVD-2026-647210.02.2026, 04:16
SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated, low-privileged user to perform background Remote Function Calls without the required S_RFC authorization in certain cases. This can result in a high impact on integrity and availability, and no impact on the confidentiality of the application.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| sap | netweaver_as_abap_kernel | 7.22 |
| sap | netweaver_as_abap_kernel | 7.53 |
| sap | netweaver_as_abap_kernel | 7.54 |
| sap | netweaver_as_abap_kernel | 7.77 |
| sap | netweaver_as_abap_kernel | 7.89 |
| sap | netweaver_as_abap_kernel | 7.93 |
| sap | netweaver_as_abap_kernel | 9.16 |
| sap | netweaver_as_abap_kernel | 9.18 |
| sap | netweaver_as_abap_kernel | 9.19 |
| sap | netweaver_as_abap_krnl64nuc | 7.22 |
| sap | netweaver_as_abap_krnl64nuc | 7.22ext:ext |
| sap | netweaver_as_abap_krnl64uc | 7.22 |
| sap | netweaver_as_abap_krnl64uc | 7.22ext:ext |
| sap | netweaver_as_abap_krnl64uc | 7.53 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
Vulnerability Media Exposure