CVE-2026-0484: Missing Authorization check in SAP NetWeaver Application Server ABAP and SAP S/4HANA
Due to missing authorization check in SAP NetWeaver Application Server ABAP and SAP S/4HANA, an authenticated attacker could access a specific transaction code and modify the text data in the system. This vulnerability has a high impact on integrity of the application with no effect on the confidentiality and availability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0484?
CVE-2026-0484 has been classified as a critical vulnerability due to its potential impact on system integrity.
How do I fix CVE-2026-0484?
To fix CVE-2026-0484, apply the latest security patches provided by SAP for both SAP NetWeaver Application Server ABAP and SAP S/4HANA.
Who is affected by CVE-2026-0484?
CVE-2026-0484 affects users of SAP NetWeaver Application Server ABAP and SAP S/4HANA that have not implemented the necessary authorization checks.
What kind of attack can exploit CVE-2026-0484?
An authenticated attacker can exploit CVE-2026-0484 to access specific transaction codes and modify text data within the affected system.
When was CVE-2026-0484 disclosed?
CVE-2026-0484 was disclosed in October 2026.