← back
CVE-2026-24309

Missing Authorization check in SAP NetWeaver Application Server for ABAP

CVSS 6.4 MEDIUMEPSS 0.2%CWE-862
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 6.4EPSS 0.2%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
10 Mar 2026Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Due to missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker could execute specific ABAP function module to read, modify or insert entries into the database configuration table of the ABAP system. This unauthorized content change could lead to reduced system performance or interruptions. The vulnerability has low impact on the application's integrity and availability, with no effect on confidentiality.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:L

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →