
PEACH
Un framework di isolamento del tenant
CVE-2026-58236 is an OS command injection vulnerability (CWE-78) in SAP NetWeaver Application Server ABAP and ABAP Platform that allows a high-privileged attacker to bypass missing security controls on an internal code path, leading to operating system command execution. It was published on August 11, 2026, as part of SAP's Security Patch Day. Affected kernel versions include KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.53, KERNEL 7.22, 7.54, 7.77, 7.93, and 9.16. The vulnerability carries a CVSS v3.1 base score of 5.5 (Medium) (GitHub Advisory, SAP Note).
The root cause is classified as CWE-78 (Improper Neutralization of Special Elements used in an OS Command), where SAP NetWeaver AS ABAP fails to properly sanitize input on an internal code path, allowing injected OS commands to be passed to the underlying operating system. The attack vector is network-based with low complexity, but exploitation requires high privileges — meaning the attacker must already hold elevated access within the SAP system. The vulnerability bypasses missing security controls on a specific internal code path rather than exploiting an externally exposed interface directly. No public proof-of-concept code or detailed technical write-ups have been identified at this time (GitHub Advisory, SAP Note).
Successful exploitation results in no confidentiality impact, low integrity impact, and high availability impact. An attacker with high privileges can execute arbitrary OS-level commands that write to the operating system or stop the SAP system entirely, causing significant service disruption. While data exfiltration is not a direct consequence, the ability to halt the SAP system poses a serious operational risk for organizations relying on SAP for critical business processes (GitHub Advisory).
There is currently no evidence of public proof-of-concept exploit code or active in-the-wild exploitation for CVE-2026-58236. The EPSS score is approximately 0.377%, indicating a low near-term exploitation probability. The NVD SSVC assessment classifies exploitation as "none" and the technical impact as "partial." The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and no threat actor attribution has been reported (GitHub Advisory, SAP Note).
SAP has addressed this vulnerability as part of its August 2026 Security Patch Day. Organizations should apply the relevant SAP Security Note 3745182 via the SAP Support Portal to obtain the patched kernel versions. As an interim measure, restrict high-privilege access to SAP NetWeaver AS ABAP systems to only trusted administrators, and monitor system audit logs for suspicious OS command execution attempts. Refer to the SAP Security Patch Day page for the full list of affected kernel versions and corresponding patches (SAP Note, SAP Patch Day).
Security firms covering SAP's August 2026 Patch Day, including Onapsis, SecurityBridge, and RedRays, published blog posts summarizing the monthly advisories, which included CVE-2026-58236 among other vulnerabilities. CyberSecurityNews and Cryptika also covered the broader SAP August 2026 patch release, noting vulnerabilities allowing malicious code injection. No specific high-profile researcher commentary or significant social media discussion focused exclusively on this CVE has been identified (Onapsis Blog, SecurityBridge Blog, RedRays Blog).
Fonte: Questo report è stato generato utilizzando l'intelligenza artificiale
Valutazione gratuita delle vulnerabilità
Valuta le tue pratiche di sicurezza cloud in 9 domini di sicurezza per confrontare il tuo livello di rischio e identificare le lacune nelle tue difese.
Richiedi una demo personalizzata
"La migliore esperienza utente che abbia mai visto offre piena visibilità ai carichi di lavoro cloud."
"Wiz fornisce un unico pannello di controllo per vedere cosa sta succedendo nei nostri ambienti cloud."
"Sappiamo che se Wiz identifica qualcosa come critico, in realtà lo è."