VDB
CVE-2026-0506
CVE-2026-0506
PUBLISHED
CVSS 8.100000381469727 HIGH
Due to a Missing Authorization Check vulnerability in Application Server ABAP and ABAP Platform, an authenticated attacker could misuse an RFC function to execute form routines (FORMs) in the ABAP system. Successful exploitation could allow the attacker to write or modify data accessible via FORMs and invoke system functionality exposed via FORMs, resulting in a high impact on integrity and availability, while confidentiality remains unaffected.
EPSS 0.07% · 22.6th percentile
Risk Scores
CVSS 3.1
8.100000381469727
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
EPSS Score
0.07%
22.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| sap | netweaver_application_server_abap | 816, 701, 702 |
| SAP_SE | SAP NetWeaver Application Server ABAP and ABAP Platform | SAP_BASIS 700, *, SAP_BASIS 702 |
Timeline
- Jan 13, 2026 EPSS Score
- Jan 13, 2026 CVE Published
- Jan 13, 2026 PoC Published
- Jan 13, 2026 PoC Published
- Jan 13, 2026 PoC Published
- Jan 13, 2026 PoC Published
- Jan 13, 2026 CVE Updated
- Jan 13, 2026 PoC Published
- Jan 13, 2026 PoC Published
- Jan 13, 2026 PoC Published
- Jan 13, 2026 PoC Published
- Jan 16, 2026 EPSS Score