SAP NetWeaver AppSrv ABAP: Auth Bypass Allows DB Config Mod
CVE-2026-24309 Published on March 10, 2026

Missing Authorization check in SAP NetWeaver Application Server for ABAP
Due to missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker could execute specific ABAP function module to read, modify or insert entries into the database configuration table of the ABAP system. This unauthorized content change could lead to reduced system performance or interruptions. The vulnerability has low impact on the application's integrity and availability, with no effect on confidentiality.

NVD

Vulnerability Analysis

CVE-2026-24309 can be exploited with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality, with no impact on integrity and availability.

Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
LOW
User Interaction:
NONE
Scope:
CHANGED
Confidentiality Impact:
NONE
Integrity Impact:
LOW
Availability Impact:
LOW

Weakness Type

What is an AuthZ Vulnerability?

The software does not perform an authorization check when an actor attempts to access a resource or perform an action.

CVE-2026-24309 has been classified to as an AuthZ vulnerability or weakness.


Products Associated with CVE-2026-24309

Want to know whenever a new CVE is published for SAP Netweaver Application Server Abap? stack.watch will email you.

 

Affected Versions

SAP_SE SAP NetWeaver Application Server for ABAP: