CVE-2026-0506: Missing Authorization check in SAP NetWeaver Application Server ABAP and ABAP Platform
Due to a Missing Authorization Check vulnerability in Application Server ABAP and ABAP Platform, an authenticated attacker could misuse an RFC function to execute form routines (FORMs) in the ABAP system. Successful exploitation could allow the attacker to write or modify data accessible via FORMs and invoke system functionality exposed via FORMs, resulting in a high impact on integrity and availability, while confidentiality remains unaffected.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0506?
CVE-2026-0506 is considered a critical vulnerability due to its potential to allow authenticated attackers to execute unauthorized actions in the SAP system.
How do I fix CVE-2026-0506?
To fix CVE-2026-0506, SAP users should apply the latest security patches provided by SAP for the affected products.
What are the consequences of CVE-2026-0506?
The consequences of CVE-2026-0506 include unauthorized access to execute harmful form routines, which can compromise the integrity of the SAP system.
Who is affected by CVE-2026-0506?
CVE-2026-0506 affects users of SAP NetWeaver Application Server ABAP and SAP ABAP Platform that have not implemented proper authorization checks.
Is CVE-2026-0506 actively exploited?
As of the current information, there are no known active exploits for CVE-2026-0506, but users are strongly advised to patch their systems promptly.