CVE-2026-0506: SAP NetWeaver Application Server Abap

High severity, CVSS 8.1. EPSS: 0.3% chance of exploitation in the next 30 days.

Due to a Missing Authorization Check vulnerability in Application Server ABAP and ABAP Platform, an authenticated attacker could misuse an RFC function to execute form routines (FORMs) in the ABAP system. Successful exploitation could allow the attacker to write or modify data accessible via FORMs and invoke system functionality exposed via FORMs, resulting in a high impact on integrity and availability, while confidentiality remains unaffected.

Affected products

  • SAP NetWeaver Application Server Abap: version 700 only; version 701 only; version 702 only; version 731 only; version 740 only; version 750 only; …

Published 2026-01-13. Last modified 2026-06-17.