πŸ” CVE Alert

CVE-2026-58246

MEDIUM 4.3

Information Disclosure vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform

CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th

SAP NetWeaver Application Server for ABAP and ABAP Platform writes sensitive session identifier information into a diagnostic trace when the trace is activated by a privileged user. An attacker with access to the resulting trace data could obtain identifiers that allow impersonation of legitimate users during their validity period.Β This leads to high impact on confidentiality. Integrity and availability are not impacted.

CWE CWE-497
Vendor sap_se
Product sap netweaver application server for abap
Published Jul 28, 2026
Stay Ahead of the Next One

Get instant alerts for sap_se sap netweaver application server for abap

Be the first to know when new medium vulnerabilities affecting sap_se sap netweaver application server for abap are published β€” delivered to Slack, Telegram or Discord.

Get Free Alerts β†’ Free Β· No credit card Β· 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N
Attack Vector
Adjacent
Attack Complexity
Low
Privileges Required
High
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

SAP_SE / SAP NetWeaver Application Server for ABAP
SAP_BASIS 740 SAP_BASIS 750 SAP_BASIS 751 SAP_BASIS 752 SAP_BASIS 753 SAP_BASIS 754 SAP_BASIS 755 SAP_BASIS 756 SAP_BASIS 757 SAP_BASIS 758 SAP_BASIS 795

References

NVD β†— CVE.org β†— EPSS Data β†—
me.sap.com: https://me.sap.com/notes/3413033 url.sap: https://url.sap/sapsecuritypatchday