CRITICAL · 9.6

CVE-2026-0509

SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated, low-privileged user to perform background Remote Function Calls without the required S_RFC authorization in certain cas...

Vulnerability Description

SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated, low-privileged user to perform background Remote Function Calls without the required S_RFC authorization in certain cases. This can result in a high impact on integrity and availability, and no impact on the confidentiality of the application.

CVSS Score

9.6

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality
NONE
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
SapNetweaver As Abap Kernel7.22
SapNetweaver As Abap Krnl64Nuc7.22
SapNetweaver As Abap Krnl64Uc7.22

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-0509?

CVE-2026-0509 is a vulnerability with a CVSS score of 9.6 (CRITICAL). SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated, low-privileged user to perform background Remote Function Calls without the required S_RFC authorization in certain cas...

How severe is CVE-2026-0509?

CVE-2026-0509 has been rated CRITICAL with a CVSS base score of 9.6/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2026-0509?

Check the references section above for vendor advisories and patch information. Affected products include: Sap Netweaver As Abap Kernel, Sap Netweaver As Abap Krnl64Nuc, Sap Netweaver As Abap Krnl64Uc.