CVE-2026-58241: Missing Authorization Check in SAP NetWeaver and ABAP Platform (Change and Transport System - Customer Transport Integration Wizard)
SAP NetWeaver and ABAP Platform (Change and Transport System - Customer Transport Integration Wizard) allows a low-privileged user to modify configuration tables that control access to data objects during specific operations. These unauthorized modifications could result in processing delays and operational disruption, leading to a low impact on the integrity and availability of the application with no impact on confidentiality.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-58241?
The severity of CVE-2026-58241 is rated as medium with a score of 4.2.
How do I fix CVE-2026-58241?
To fix CVE-2026-58241, you should implement the latest patches provided by SAP for the SAP NetWeaver and ABAP Platform.
What kind of impact can CVE-2026-58241 have on my system?
CVE-2026-58241 can allow a low-privileged user to modify configuration tables, leading to potential processing delays and unauthorized access to data objects.
What products are affected by CVE-2026-58241?
CVE-2026-58241 affects the SAP NetWeaver and ABAP Platform specifically within the Change and Transport System.
Who could exploit the CVE-2026-58241 vulnerability?
CVE-2026-58241 could be exploited by low-privileged users with access to the Customer Transport Integration Wizard.