CVE-2026-0486 PUBLISHED

Missing Authorization Check in ABAP based SAP systems

Assigner: sap
Reserved: 09.12.2025 Published: 10.02.2026 Updated: 10.02.2026

In ABAP based SAP systems a remote enabled function module does not perform necessary authorization checks for an authenticated user resulting in disclosure of system information.This has low impact on confidentiality. Integrity and availability are not impacted.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
CVSS Score: 5

Product Status

Vendor SAP_SE
Product ABAP based SAP systems
Versions Default: unaffected
  • Version ST-PI 2005_1_700 is affected
  • Version 2008_1_710 is affected
  • Version 740 is affected
  • Version 758 is affected

References

Problem Types