CVE-2026-0486
Missing Authorization Check in ABAP based SAP systems
Vexday Risk Score
13Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 5EPSS 0.2%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
10 feb 2026Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
In ABAP based SAP systems a remote enabled function module does not perform necessary authorization checks for an authenticated user resulting in disclosure of system information.This has low impact on confidentiality. Integrity and availability are not impacted.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
Productos afectados
SAP_SE · ABAP based SAP systems¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →