CVE-2026-0488: Code Injection vulnerability in SAP CRM and SAP S/4HANA (Scripting Editor)
An authenticated attacker in SAP CRM and SAP S/4HANA (Scripting Editor) could exploit a flaw in a generic function module call and execute unauthorized critical functionalities, which includes the ability to execute an arbitrary SQL statement. This leads to a full database compromise with high impact on confidentiality, integrity, and availability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0488?
CVE-2026-0488 is a critical severity vulnerability due to its potential to allow code injection by authenticated attackers.
How do I fix CVE-2026-0488?
To fix CVE-2026-0488, ensure that your SAP CRM and SAP S/4HANA systems are updated with the latest security patches provided by SAP.
What products are affected by CVE-2026-0488?
CVE-2026-0488 affects SAP CRM and SAP S/4HANA platforms that utilize the Scripting Editor feature.
Can CVE-2026-0488 be exploited remotely?
CVE-2026-0488 requires authentication, meaning it cannot be exploited remotely without valid credentials.
What type of vulnerabilities does CVE-2026-0488 represent?
CVE-2026-0488 represents a code injection vulnerability that may allow an attacker to execute unauthorized commands on affected SAP systems.