VDB

CVE-2026-0506

CVE-2026-0506 PUBLISHED CVSS 8.100000381469727 HIGH

Due to a Missing Authorization Check vulnerability in Application Server ABAP and ABAP Platform, an authenticated attacker could misuse an RFC function to execute form routines (FORMs) in the ABAP system. Successful exploitation could allow the attacker to write or modify data accessible via FORMs and invoke system functionality exposed via FORMs, resulting in a high impact on integrity and availability, while confidentiality remains unaffected.

EPSS 0.07% · 22.6th percentile

Risk Scores

CVSS 3.1
8.100000381469727
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
EPSS Score
0.07%
22.6th percentile

Affected Products

VendorProductVersions
sapnetweaver_application_server_abap816, 701, 702
SAP_SESAP NetWeaver Application Server ABAP and ABAP PlatformSAP_BASIS 700, *, SAP_BASIS 702

Timeline

  • Jan 13, 2026 EPSS Score
  • Jan 13, 2026 CVE Published
  • Jan 13, 2026 PoC Published
  • Jan 13, 2026 PoC Published
  • Jan 13, 2026 PoC Published
  • Jan 13, 2026 PoC Published
  • Jan 13, 2026 CVE Updated
  • Jan 13, 2026 PoC Published
  • Jan 13, 2026 PoC Published
  • Jan 13, 2026 PoC Published
  • Jan 13, 2026 PoC Published
  • Jan 16, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›