← Back

CVE-2026-0488

nvd nist
Published: Feb 10, 2026Modified: Feb 17, 2026

JSON object

Loading...
9.9
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Exploitability: 3.1 / Impact: 6.0
Source: NVD

Description

An authenticated attacker in SAP CRM and SAP S/4HANA (Scripting Editor) could exploit a flaw in a generic function module call and execute unauthorized critical functionalities, which includes the ability to execute an arbitrary SQL statement. This leads to a full database compromise with high impact on confidentiality, integrity, and availability.

Affected (18)

3 products
Netweaver Application Server Abap
S/4hana
Webclient Ui Framework
Configuration A
18 vulnerable
Vulnerable SoftwareAffected Versions
Version 700
Sap
Version 102
Version 103
Version 104
Version 105
Version 106
Version 107
Version 108
Version 109
Sap
Version 700
Version 701
Version 730
Version 731
Version 746
Version 747
Version 748
Version 800
Version 801

References (2)

Source: cna@sap.com
Permissions Required
Source: cna@sap.com
Vendor Advisory

Timeline

No history available yet.