← All CVEs

CVE-2026-0509

critical · 9.6

SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated, low-privileged user to perform background Remote Function Calls without the required S_RFC authorization in certain cases. This can result in a high impact on integrity and availability, and no impact on the confidentiality of the application.

9.6
CVSS
0.4%
EPSS (exploit prob.)
29th
EPSS percentile
2026-02-10
Published

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H

Weaknesses

CWE-862

Affected products

VendorProductAffected versions
sapnetweaver_as_abap_kernel7.22
sapnetweaver_as_abap_kernel7.53
sapnetweaver_as_abap_kernel7.54
sapnetweaver_as_abap_kernel7.77
sapnetweaver_as_abap_kernel7.89
sapnetweaver_as_abap_kernel7.93
sapnetweaver_as_abap_kernel9.16
sapnetweaver_as_abap_kernel9.18
sapnetweaver_as_abap_kernel9.19
sapnetweaver_as_abap_krnl64nuc7.22
sapnetweaver_as_abap_krnl64nuc7.22ext
sapnetweaver_as_abap_krnl64uc7.22
sapnetweaver_as_abap_krnl64uc7.22ext
sapnetweaver_as_abap_krnl64uc7.53

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2026-0509