Wiz tritt Google Cloud bei: Gemeinsam Magie erschaffen

CVE-2026-58236
SAP NetWeaver Application Server ABAP Schwachstellenanalyse und -minderung

Überblick

CVE-2026-58236 is an OS command injection vulnerability (CWE-78) in SAP NetWeaver Application Server ABAP and ABAP Platform that allows a high-privileged attacker to bypass missing security controls on an internal code path, leading to operating system command execution. It was published on August 11, 2026, as part of SAP's Security Patch Day. Affected kernel versions include KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.53, KERNEL 7.22, 7.54, 7.77, 7.93, and 9.16. The vulnerability carries a CVSS v3.1 base score of 5.5 (Medium) (GitHub Advisory, SAP Note).

Technische Details

The root cause is classified as CWE-78 (Improper Neutralization of Special Elements used in an OS Command), where SAP NetWeaver AS ABAP fails to properly sanitize input on an internal code path, allowing injected OS commands to be passed to the underlying operating system. The attack vector is network-based with low complexity, but exploitation requires high privileges — meaning the attacker must already hold elevated access within the SAP system. The vulnerability bypasses missing security controls on a specific internal code path rather than exploiting an externally exposed interface directly. No public proof-of-concept code or detailed technical write-ups have been identified at this time (GitHub Advisory, SAP Note).

Aufprall

Successful exploitation results in no confidentiality impact, low integrity impact, and high availability impact. An attacker with high privileges can execute arbitrary OS-level commands that write to the operating system or stop the SAP system entirely, causing significant service disruption. While data exfiltration is not a direct consequence, the ability to halt the SAP system poses a serious operational risk for organizations relying on SAP for critical business processes (GitHub Advisory).

Ausnutzbarkeit

There is currently no evidence of public proof-of-concept exploit code or active in-the-wild exploitation for CVE-2026-58236. The EPSS score is approximately 0.377%, indicating a low near-term exploitation probability. The NVD SSVC assessment classifies exploitation as "none" and the technical impact as "partial." The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and no threat actor attribution has been reported (GitHub Advisory, SAP Note).

Risikominderung und Problemumgehungen

SAP has addressed this vulnerability as part of its August 2026 Security Patch Day. Organizations should apply the relevant SAP Security Note 3745182 via the SAP Support Portal to obtain the patched kernel versions. As an interim measure, restrict high-privilege access to SAP NetWeaver AS ABAP systems to only trusted administrators, and monitor system audit logs for suspicious OS command execution attempts. Refer to the SAP Security Patch Day page for the full list of affected kernel versions and corresponding patches (SAP Note, SAP Patch Day).

Reaktionen der Community

Security firms covering SAP's August 2026 Patch Day, including Onapsis, SecurityBridge, and RedRays, published blog posts summarizing the monthly advisories, which included CVE-2026-58236 among other vulnerabilities. CyberSecurityNews and Cryptika also covered the broader SAP August 2026 patch release, noting vulnerabilities allowing malicious code injection. No specific high-profile researcher commentary or significant social media discussion focused exclusively on this CVE has been identified (Onapsis Blog, SecurityBridge Blog, RedRays Blog).

Zusätzliche Ressourcen


QuelleDieser Bericht wurde mithilfe von KI erstellt

Verwandt SAP NetWeaver Application Server ABAP Schwachstellen:

CVE-Kennung

Strenge

Punktzahl

Technologieen

Name der Komponente

CISA KEV-Exploit

Hat fix

Veröffentlichungsdatum

CVE-2026-44756CRITICAL10
  • SAP NetWeaver Application Server ABAP logoSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
NeinJaSep 08, 2026
CVE-2026-58240CRITICAL9.8
  • SAP NetWeaver Application Server ABAP logoSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
NeinJaSep 08, 2026
CVE-2026-66767HIGH7.7
  • SAP NetWeaver Application Server ABAP logoSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
NeinJaSep 08, 2026
CVE-2026-66779MEDIUM6.3
  • SAP NetWeaver Application Server ABAP logoSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
NeinNeinAug 11, 2026
CVE-2026-58236MEDIUM5.5
  • SAP NetWeaver Application Server ABAP logoSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
NeinJaAug 11, 2026

Kostenlose Schwachstellenbewertung

Benchmarking Ihrer Cloud-Sicherheitslage

Bewerten Sie Ihre Cloud-Sicherheitspraktiken in 9 Sicherheitsbereichen, um Ihr Risikoniveau zu bewerten und Lücken in Ihren Abwehrmaßnahmen zu identifizieren.

Bewertung anfordern

Eine personalisierte Demo anfordern

Sind Sie bereit, Wiz in Aktion zu sehen?

"Die beste Benutzererfahrung, die ich je gesehen habe, bietet vollständige Transparenz für Cloud-Workloads."
David EstlickCISO
"„Wiz bietet eine zentrale Oberfläche, um zu sehen, was in unseren Cloud-Umgebungen vor sich geht.“ "
Adam FletcherSicherheitsbeauftragter
"„Wir wissen, dass, wenn Wiz etwas als kritisch identifiziert, es auch wirklich kritisch ist.“"
Greg PoniatowskiLeiter Bedrohungs- und Schwachstellenmanagement