CVE-2026-58241 PUBLISHED

Missing Authorization Check in SAP NetWeaver and ABAP Platform (Change and Transport System - Customer Transport Integration Wizard)

Assigner: sap
Reserved: 29.06.2026 Published: 11.08.2026 Updated: 11.08.2026

SAP NetWeaver and ABAP Platform (Change and Transport System - Customer Transport Integration Wizard) allows a low-privileged user to modify configuration tables that control access to data objects during specific operations. These unauthorized modifications could result in processing delays and operational disruption, leading to a low impact on the integrity and availability of the application with no impact on confidentiality.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L
CVSS Score: 4.2

Product Status

Vendor SAP_SE
Product SAP NetWeaver and ABAP Platform (Change and Transport System - Customer Transport Integration Wizard
Versions Default: unaffected
  • Version SAP_BASIS 740 is affected
  • Version SAP_BASIS 750 is affected
  • Version SAP_BASIS 751 is affected
  • Version SAP_BASIS 752 is affected
  • Version SAP_BASIS 753 is affected
  • Version SAP_BASIS 754 is affected
  • Version SAP_BASIS 755 is affected
  • Version SAP_BASIS 756 is affected
  • Version SAP_BASIS 757 is affected
  • Version SAP_BASIS 758 is affected
  • Version SAP_BASIS 816 is affected

References

Problem Types