VDB

CVE-2026-0507

CVE-2026-0507 PUBLISHED CVSS 8.399999618530273 HIGH

Due to an OS Command Injection vulnerability in SAP Application Server for ABAP and SAP NetWeaver RFCSDK, an authenticated attacker with administrative access and adjacent network access could upload specially crafted content to the server. If processed by the application, this content enables execution of arbitrary operating system commands. Successful exploitation could lead to full compromise of the system�s confidentiality, integrity, and availability.

EPSS 1.37% · 80.6th percentile

Risk Scores

CVSS 3.1
8.399999618530273
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
EPSS Score
1.37%
80.6th percentile

Affected Products

VendorProductVersions
SAPWily Introscope Enterprise Manager
SAPHANA database
SAPERP Central Component and S/4HANA
SAPLandscape Transformation
SAPS/4HANA Private Cloud and On-Premise
SAPApplication Server for ABAP and NetWeaver RFCSDK
SAPS/4HANA
SAPBusiness Server Pages Application
SAPFiori App
SAPSupplier Relationship Management
SAPNetWeaver Enterprise Portal
SAPIdentity Management
SAP_SESAP Application Server for ABAP and SAP NetWeaver RFCSDK7.77, 7.89, 7.93
SAPBusiness Connector
SAPNetWeaver Application Server ABAP et ABAP Platform

Timeline

  • Jan 13, 2026 EPSS Score
  • Jan 13, 2026 CVE Published
  • Jan 13, 2026 PoC Published
  • Jan 13, 2026 PoC Published
  • Jan 13, 2026 PoC Published
  • Jan 13, 2026 PoC Published
  • Jan 13, 2026 PoC Published
  • Jan 13, 2026 PoC Published
  • Jan 13, 2026 PoC Published
  • Jan 16, 2026 EPSS Score
  • Jan 19, 2026 EPSS Score
  • Jan 22, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›