CVE-2026-0491: Code Injection vulnerability in SAP Landscape Transformation
SAP Landscape Transformation allows an attacker with admin privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injection of arbitrary ABAP code/OS commands into the system, bypassing essential authorization checks. This vulnerability effectively functions as a backdoor, creating the risk of full system compromise, undermining the confidentiality, integrity and availability of the system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0491?
CVE-2026-0491 is classified as a critical vulnerability due to its potential for arbitrary code injection.
How do I fix CVE-2026-0491?
To mitigate CVE-2026-0491, it is essential to apply the latest security patches provided by SAP for SAP Landscape Transformation.
Who is affected by CVE-2026-0491?
CVE-2026-0491 affects environments running SAP Landscape Transformation with admin privileges that can exploit the vulnerability.
What type of vulnerability is CVE-2026-0491?
CVE-2026-0491 is a code injection vulnerability that allows attackers to inject arbitrary ABAP code or OS commands.
What are the risks associated with CVE-2026-0491?
The risks of CVE-2026-0491 include unauthorized access, data manipulation, or complete system compromise due to code execution.