CVE-2026-24309: SAP NetWeaver Application Server Abap

Medium severity, CVSS 6.4. EPSS: 0.2% chance of exploitation in the next 30 days.

Due to missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker could execute specific ABAP function module to read, modify or insert entries into the database configuration table of the ABAP system. This unauthorized content change could lead to reduced system performance or interruptions. The vulnerability has low impact on the application's integrity and availability, with no effect on confidentiality.

Affected products

  • SAP NetWeaver Application Server Abap: version 700 only; version 701 only; version 702 only; version 731 only; version 740 only; version 750 only; …

Published 2026-03-10. Last modified 2026-06-17.