Vulnerability Description
An authenticated attacker in SAP CRM and SAP S/4HANA (Scripting Editor) could exploit a flaw in a generic function module call and execute unauthorized critical functionalities, which includes the ability to execute an arbitrary SQL statement. This leads to a full database compromise with high impact on confidentiality, integrity, and availability.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sap | Netweaver Application Server Abap | 700 |
| Sap | S\/4Hana | 102 |
| Sap | Webclient Ui Framework | 700 |
Related Weaknesses (CWE)
References
- https://me.sap.com/notes/3697099Permissions Required
- https://url.sap/sapsecuritypatchdayVendor Advisory
FAQ
What is CVE-2026-0488?
CVE-2026-0488 is a vulnerability with a CVSS score of 9.9 (CRITICAL). An authenticated attacker in SAP CRM and SAP S/4HANA (Scripting Editor) could exploit a flaw in a generic function module call and execute unauthorized critical functionalities, which includes the abi...
How severe is CVE-2026-0488?
CVE-2026-0488 has been rated CRITICAL with a CVSS base score of 9.9/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-0488?
Check the references section above for vendor advisories and patch information. Affected products include: Sap Netweaver Application Server Abap, Sap S\/4Hana, Sap Webclient Ui Framework.