CVE-2026-34257: SAP NetWeaver Application Server Abap

Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.

Due to an Open Redirect vulnerability in SAP NetWeaver Application Server ABAP, an unauthenticated attacker could craft malicious URL that, if accessed by a victim, they could be redirected to the page controlled by the attacker. This causes low impact on confidentiality and integrity of the application with no impact on availability.

Affected products

  • SAP NetWeaver Application Server Abap: version 700 only; version 701 only; version 702 only; version 731 only; version 740 only; version 750 only; …

Published 2026-04-14. Last modified 2026-06-17.