CVE-2026-0509: Missing Authorization check in SAP NetWeaver Application Server ABAP and ABAP Platform
SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated, low-privileged user to perform background Remote Function Calls without the required SRFC authorization in certain cases. This can result in a high impact on integrity and availability, and no impact on the confidentiality of the application.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0509?
CVE-2026-0509 is considered a high-severity vulnerability due to the potential for unauthorized access to sensitive functions.
How do I fix CVE-2026-0509?
To fix CVE-2026-0509, apply the latest security patches provided by SAP for the affected versions of SAP NetWeaver Application Server ABAP and ABAP Platform.
Who is affected by CVE-2026-0509?
CVE-2026-0509 affects users of SAP NetWeaver Application Server ABAP and SAP ABAP Platform who have low privileges.
What impact does CVE-2026-0509 have?
CVE-2026-0509 allows an authenticated user to perform unauthorized Remote Function Calls, potentially leading to unauthorized data access.
Is there a workaround for CVE-2026-0509?
Currently, SAP recommends applying security patches as the primary method to mitigate CVE-2026-0509, as no effective workaround is available.