Back

HIGH

Missing Authorization check in Application Server ABAP of SAP NetWeaver and ABAP Platform

Published Jun 9, 2026

Description

Application server ABAP does not perform necessary authorization checks for an authenticated user allowing an attacker to execute a report generation command which could overwrite information belonging to another user, resulting in escalation of privileges. This has high impact on integrity with low impact on availability and no impact on confidentiality of the application.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner sap
Published Jun 9, 2026
Updated Jun 10, 2026
Reserved May 7, 2026
CISA Vulnrichment
Updated Jun 10, 2026
NVD
Status Awaiting Analysis
Modified Jul 23, 2026
Red Hat
Severity n/a
Public date n/a