Sceawere

Vulnerability Detail

CVE-2026-58236UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

SAP NetWeaver OS Command Execution

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.5
Creation Date
4h ago
Vendor
SAP_SE
Product
SAP NetWeaver Application Server ABAP and ABAP Platform
Attack Type
CWE-78: Improper Neutralization of Special Elements used in an OS Command
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H
Attack Complexity
LOW

Narrative and Response

Description

SAP NetWeaver Application Server ABAP and ABAP Platform allow an attacker with high privileges to bypass missing security controls on an internal code path leading to operating system command execution. Successful exploitation could allow the attacker to execute OS-level commands that write to the operating system or stop the SAP system, resulting in no impact on confidentiality, low impact on integrity, and high impact on availability.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.5",
  "pubDate": "2026-08-11T01:17:21.553Z",
  "pubdate": "2026-08-11T01:17:21.553Z",
  "executiveSummary": "A security vulnerability affecting SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated attacker with high privileges to execute arbitrary operating system commands.\nThe vulnerability stems from missing security controls on an internal code path, enabling threat actors to bypass authorization barriers and interact directly with the underlying host operating system.\nSuccessful exploitation results in high impact on system availability, as the execution of malicious commands can lead to the termination of the SAP system or unauthorized write operations to the filesystem.\nThe confidentiality impact is rated as none, while integrity impact is low.\nExploitation requires high privileges within the target SAP system, meaning an attacker must already compromise an administrative or privileged account to initiate the attack sequence.\nThe risk implication is critical for enterprise environments relying on SAP infrastructure, as system downtime directly disrupts business operations.\nOrganizations must apply vendor-supplied patches and restrict high-privilege access to mitigate the risk of unauthorized operating system command execution.",
  "technicalDetails": "The vulnerability resides within SAP NetWeaver Application Server ABAP and ABAP Platform, specifically impacting internal code paths responsible for executing system-level operations.\nThe root cause of the vulnerability is the absence of adequate security controls and input validation mechanisms along a privileged internal execution path.\nAn attacker must possess high privileges within the SAP environment to initiate the attack, leveraging authorized access to reach the vulnerable internal code path.\nThe attack flow begins when the privileged user invokes specific administrative functions or internal routines that fail to properly sanitize input or restrict execution context.\nBy bypassing the missing security controls, the attacker injects or passes arbitrary operating system commands through the vulnerable component.\nThe underlying operating system executes the commands with the privileges of the SAP process context.\nPost-exploitation impact includes the ability to write arbitrary data to the operating system filesystem or execute commands designed to stop the SAP system entirely, resulting in a complete denial of service.\nNetwork exposure and authentication requirements dictate that the attacker must have network access to the SAP NetWeaver application server and authenticate with high privileges before exploitation can occur."
}
CVE-2026-58236: SAP NetWeaver OS Command Execution (MEDIUM Severity, CVSS: 5.5) - Sceawere