CVE-2026-0498: Code Injection vulnerability in SAP S/4HANA (Private Cloud and On-Premise)

Published Jan 13, 2026
·
Updated

SAP S/4HANA (Private Cloud and On-Premise) allows an attacker with admin privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injection of arbitrary ABAP code/OS commands into the system, bypassing essential authorization checks. This vulnerability effectively functions as a backdoor, creating the risk of full system compromise, undermining the confidentiality, integrity and availability of the system.

Affected Software

9 affected components
SAP S/4HANA
SAP S\/4 Hana=102
SAP S\/4 Hana=103
SAP S\/4 Hana=104
SAP S\/4 Hana=105
SAP S\/4 Hana=106
SAP S\/4 Hana=107
SAP S\/4 Hana=108
SAP S\/4 Hana=109

Remediation

Event History

Jan 13, 2026
CVE Published
via MITRE·01:13 AM
Data Sourced
via MITRE·01:13 AM
DescriptionSeverity
Data Sourced
via NVD·02:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-0498?

CVE-2026-0498 has a high severity rating due to its potential for code injection by users with admin privileges.

2

How can I fix CVE-2026-0498?

To fix CVE-2026-0498, it is recommended to apply the latest security patches provided by SAP for your installation of S/4HANA.

3

What versions of SAP S/4HANA are affected by CVE-2026-0498?

CVE-2026-0498 affects both the Private Cloud and On-Premise versions of SAP S/4HANA.

4

Who can exploit CVE-2026-0498?

CVE-2026-0498 can be exploited by an attacker who has admin privileges within the affected SAP S/4HANA system.

5

What are the potential consequences of exploiting CVE-2026-0498?

Exploitation of CVE-2026-0498 could allow attackers to inject arbitrary ABAP code or OS commands, leading to unauthorized actions within the system.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203