CVE-2026-0488: SAP NetWeaver Application Server Abap

Critical severity, CVSS 9.9. EPSS: 0.5% chance of exploitation in the next 30 days.

An authenticated attacker in SAP CRM and SAP S/4HANA (Scripting Editor) could exploit a flaw in a generic function module call and execute unauthorized critical functionalities, which includes the ability to execute an arbitrary SQL statement. This leads to a full database compromise with high impact on confidentiality, integrity, and availability.

Affected products

  • SAP NetWeaver Application Server Abap: version 700 only
  • SAP s/4hana: version 102 only; version 103 only; version 104 only; version 105 only; version 106 only; version 107 only; …
  • SAP Webclient UI Framework: version 700 only; version 701 only; version 730 only; version 731 only; version 746 only; version 747 only; …

Published 2026-02-10. Last modified 2026-06-17.