SAP Security Notes, August 2026

SAP Security Note 3714806 patches a critical memory corruption vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform, tracked as CVE-2026-34265 with a CVSS score of 9.8. An unauthenticated remote attacker can exploit improper boundary validation in DIAG protocol parsing to corrupt memory, potentially disclose sensitive information, affect system integrity, or cause system crashes. SAP has corrected the issue by introducing proper boundary checks in the affected kernel components. Customers should install the applicable kernel patch level or latest compatible SP Stack Kernel.

SAP Security Note 765948 addresses a critical code injection vulnerability in SAP Manufacturing Integration and Intelligence (MII), tracked as CVE-2026-44772 with a CVSS score of 9.9. A low-privileged remote attacker can exploit an SSRF flaw in XSL transformations to make the application process attacker-controlled external content, potentially enabling arbitrary command execution on the underlying host. Successful exploitation could severely impact confidentiality, integrity, and availability. SAP has introduced new Secure Transformer and Allowed Hosts system properties to restrict XSL sources. Customers should apply the referenced patches and configure these properties as instructed.

SAP Security Note 3758900 fixes a critical code injection vulnerability in SAP Manufacturing Integration and Intelligence (MII), tracked as CVE-2026-44758 with a CVSS score of 9.1. A highly privileged attacker with access to the XMII_IllumXSLTServlet action can submit crafted input to the vulnerable XSL transformation servlet and potentially execute arbitrary operating system commands. Successful exploitation could severely impact confidentiality, integrity, and availability. The note removes the vulnerable IllumXSLTServlet component and recommends using the XSL Transformation action block instead. Customers should apply the referenced patches and remove XMII_IllumXSLTServlet access from all roles as a temporary mitigation.

SAP Security Note 3771065 relates to a critical improper authorization vulnerability in SAP Commerce Cloud Data Hub Adapter, tracked as CVE-2026-58231 with a maximum CVSS score of 10.0. An unauthenticated attacker can abuse a default authentication client and insufficient authorization controls to submit malicious input, potentially achieving remote code execution and compromising internal components. Successful exploitation could severely impact confidentiality, integrity, and availability. The issue affects systems with the Data Hub Adapter extension enabled. Customers should upgrade to SAP Commerce Cloud 2211.55, 2211-jdk21.17, or later releases. As a temporary mitigation, access to /datahubadapter/import/** should be restricted to trusted DataHub server IP addresses using an IP Filter Set.

SAP Security Note 3772411 patches a high-severity privilege escalation vulnerability in SAP ABAP Developer Tools, tracked as CVE-2026-58243 with a CVSS score of 8.8. A low-privileged attacker can exploit insufficient authorization checks in the SQL Console to perform unauthorized database operations against SAP NetWeaver AS ABAP, potentially reading sensitive data, modifying application data, or disrupting access for legitimate users. The issue stems from the improper use of host expressions in SQL statements. SAP has restricted this functionality and recommends applying the referenced patches. As a temporary mitigation, customers should remove S_TABU_NAM and S_TABU_DIS from users that do not require the authorizations.

SAP Security Note 3773304 fixes a high-severity remote code execution vulnerability in the Enhanced Change and Transport System (CTS+) Attach Tool (ctsattach), tracked as CVE-2026-58233 with a CVSS score of 7.6. An authenticated attacker can provide a malicious archive file that exploits insecure deserialization in a third-party library when processed by a victim, potentially enabling remote code execution, disclosure of sensitive information, and control of affected system processes. All versions of ctsattach are vulnerable and no fixed version is available. SAP has discontinued the tool and instructs customers to immediately stop using it and remove all installed copies, using alternative transport methods documented by SAP.

Share the Post: