CVE-2020-26819: SAP NetWeaver Application Server Abap

High severity, CVSS 8.8. EPSS: 0.9% chance of exploitation in the next 30 days.

SAP NetWeaver AS ABAP (Web Dynpro), versions - 731, 740, 750, 751, 752, 753, 754, 755, 782, allows an authenticated user to access Web Dynpro components, that allows them to read and delete database logfiles because of Improper Access Control.

Affected products

  • SAP NetWeaver Application Server Abap: version 731 only; version 740 only; version 750 only; version 751 only; version 752 only; version 753 only; …

Published 2020-11-10. Last modified 2026-06-17.