SAP NetWeaver AS ABAP: Auth Bypass Allows Sensitive DB Read (CVE-2026-24310)
CVE-2026-24310 Published on March 10, 2026
Missing Authorization check in SAP NetWeaver Application Server for ABAP
Due to missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker could execute specific ABAP function module and read the sensitive information from database catalog of the ABAP system. This vulnerability has low impact on the application's confidentiality with no effect on the integrity and availability.
Vulnerability Analysis
CVE-2026-24310 is exploitable with network access, and requires small amount of user privileges. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to have a small impact on confidentiality, a small impact on integrity and availability.
Weakness Type
What is an AuthZ Vulnerability?
The software does not perform an authorization check when an actor attempts to access a resource or perform an action.
CVE-2026-24310 has been classified to as an AuthZ vulnerability or weakness.
Products Associated with CVE-2026-24310
Want to know whenever a new CVE is published for SAP Netweaver Application Server Abap? stack.watch will email you.
Affected Versions
SAP_SE SAP NetWeaver Application Server for ABAP:- Version SAP_BASIS 702 is affected.
- Version SAP_BASIS 731 is affected.
- Version SAP_BASIS 740 is affected.
- Version SAP_BASIS 750 is affected.
- Version SAP_BASIS 751 is affected.
- Version SAP_BASIS 752 is affected.
- Version SAP_BASIS 753 is affected.
- Version SAP_BASIS 754 is affected.
- Version SAP_BASIS 755 is affected.
- Version SAP_BASIS 756 is affected.
- Version SAP_BASIS 757 is affected.
- Version SAP_BASIS 758 is affected.
- Version SAP_BASIS 816 is affected.