CVE-2026-0498: Code Injection vulnerability in SAP S/4HANA (Private Cloud and On-Premise)
SAP S/4HANA (Private Cloud and On-Premise) allows an attacker with admin privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injection of arbitrary ABAP code/OS commands into the system, bypassing essential authorization checks. This vulnerability effectively functions as a backdoor, creating the risk of full system compromise, undermining the confidentiality, integrity and availability of the system.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0498?
CVE-2026-0498 has a high severity rating due to its potential for code injection by users with admin privileges.
How can I fix CVE-2026-0498?
To fix CVE-2026-0498, it is recommended to apply the latest security patches provided by SAP for your installation of S/4HANA.
What versions of SAP S/4HANA are affected by CVE-2026-0498?
CVE-2026-0498 affects both the Private Cloud and On-Premise versions of SAP S/4HANA.
Who can exploit CVE-2026-0498?
CVE-2026-0498 can be exploited by an attacker who has admin privileges within the affected SAP S/4HANA system.
What are the potential consequences of exploiting CVE-2026-0498?
Exploitation of CVE-2026-0498 could allow attackers to inject arbitrary ABAP code or OS commands, leading to unauthorized actions within the system.