CRITICAL
Code Injection vulnerability in SAP CRM and SAP S/4HANA (Scripting Editor)
Published Feb 10, 2026
9.9
CRITICALCVSS 3.1
EPSS 0.52%
Description
An authenticated attacker in SAP CRM and SAP S/4HANA (Scripting Editor) could exploit a flaw in a generic function module call and execute unauthorized critical functionalities, which includes the ability to execute an arbitrary SQL statement. This leads to a full database compromise with high impact on confidentiality, integrity, and availability.
Affected products
-
- Version 103StatusaffectedConstraints-
- Version 104StatusaffectedConstraints-
- Version 105StatusaffectedConstraints-
- Version 106StatusaffectedConstraints-
- Version 107StatusaffectedConstraints-
- Version 108StatusaffectedConstraints-
- Version 109StatusaffectedConstraints-
- Version 701StatusaffectedConstraints-
- Version 730StatusaffectedConstraints-
- Version 731StatusaffectedConstraints-
- Version 746StatusaffectedConstraints-
- Version 747StatusaffectedConstraints-
- Version 748StatusaffectedConstraints-
- Version 800StatusaffectedConstraints-
- Version 801StatusaffectedConstraints-
- Version S4FND 102StatusaffectedConstraints-
- Version SAP_ABA 700StatusaffectedConstraints-
- Version WEBCUIF 700StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| SAP SE | SAP CRM and SAP S/4HANA (Scripting Editor) | unaffected |
|
OR
- 700
- 102
- 103
- 104
- 105
- 106
- 107
- 108
- 109
- 700
- 701
- 730
- 731
- 746
- 747
- 748
- 800
- 801
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (2)
- https://me.sap.com/notes/3697099 Permissions Required
- https://url.sap/sapsecuritypatchday Vendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://me.sap.com/notes/3697099 | Permissions Required | |
| https://url.sap/sapsecuritypatchday | Vendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner sap
Published Feb 10, 2026
Updated Feb 26, 2026
Reserved Dec 9, 2025
Link CVE-2026-0488
CISA Vulnrichment
Updated Feb 11, 2026