CVE-2026-40129 PUBLISHED

Code Injection vulnerability in SAP Application Server ABAP for SAP NetWeaver and ABAP Platform

Assigner: sap
Reserved: 09.04.2026 Published: 12.05.2026 Updated: 12.05.2026

Due to a Code Injection vulnerability in SAP Application Server ABAP for SAP NetWeaver and ABAP Platform, an authenticated attacker could send specially crafted inputs to the application. If processed by the application, this input could be delivered to users subscribed to the channel and result in execution. Successful exploitation could enable the attacker to execute arbitrary code for other users, resulting in a low impact on the integrity, with no impact to the confidentiality and availability of the system.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CVSS Score: 4.3

Product Status

Vendor SAP_SE
Product SAP Application Server ABAP for SAP NetWeaver and ABAP Platform
Versions Default: unaffected
  • Version SAP_BASIS 740 is affected
  • Version SAP_BASIS 750 is affected
  • Version SAP_BASIS 751 is affected
  • Version SAP_BASIS 752 is affected
  • Version SAP_BASIS 753 is affected
  • Version SAP_BASIS 754 is affected
  • Version SAP_BASIS 755 is affected
  • Version SAP_BASIS 756 is affected
  • Version SAP_BASIS 757 is affected
  • Version SAP_BASIS 758 is affected
  • Version SAP_BASIS 816 is affected

References

Problem Types