VDB

CVE-2026-58233

CVE-2026-58233 PUBLISHED CVSS 7.6 HIGH

Reported by sap · Published July 14, 2026

SAP Change and Transport System Attach Tool (ctsattach) allows an authenticated attacker to supply a specially crafted archive file which, when processed by the application�s library, can trigger insecure deserialization and lead to remote code execution (RCE) on the system. Successful exploitation requires a victim to process the malicious archive, enabling the attacker to execute the RCE and extract sensitive information and gain control over the system and its processes. This vulnerability has a high impact on confidentiality and integrity of the data, with a low impact on the availability of the system.

Risk Scores

CVSS 3.1
7.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L

Affected Products

VendorProductVersions
SAP_SESAP Change and Transport System Attach Tool (ctsattach)CTS_UPLOAD_CLT 1
SAP_SESAP Change and Transport System Attach Tool (ctsattach)CTS_UPLOAD_CLT 1

Timeline

  • Jul 14, 2026 EPSS Score
  • Jul 14, 2026 Coalition ESS Score
  • Jul 14, 2026 CVE Published
  • Jul 14, 2026 CVE Updated

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›