CVE-2026-58236: 
SAP NetWeaver Application Server ABAP 脆弱性の分析と軽減

概要

CVE-2026-58236 is an OS command injection vulnerability (CWE-78) in SAP NetWeaver Application Server ABAP and ABAP Platform that allows a high-privileged attacker to bypass missing security controls on an internal code path, leading to operating system command execution. It was published on August 11, 2026, as part of SAP's Security Patch Day. Affected kernel versions include KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.53, KERNEL 7.22, 7.54, 7.77, 7.93, and 9.16. The vulnerability carries a CVSS v3.1 base score of 5.5 (Medium) (GitHub Advisory, SAP Note).

技術的な詳細

The root cause is classified as CWE-78 (Improper Neutralization of Special Elements used in an OS Command), where SAP NetWeaver AS ABAP fails to properly sanitize input on an internal code path, allowing injected OS commands to be passed to the underlying operating system. The attack vector is network-based with low complexity, but exploitation requires high privileges — meaning the attacker must already hold elevated access within the SAP system. The vulnerability bypasses missing security controls on a specific internal code path rather than exploiting an externally exposed interface directly. No public proof-of-concept code or detailed technical write-ups have been identified at this time (GitHub Advisory, SAP Note).

影響

Successful exploitation results in no confidentiality impact, low integrity impact, and high availability impact. An attacker with high privileges can execute arbitrary OS-level commands that write to the operating system or stop the SAP system entirely, causing significant service disruption. While data exfiltration is not a direct consequence, the ability to halt the SAP system poses a serious operational risk for organizations relying on SAP for critical business processes (GitHub Advisory).

エクスプロイト可能性

There is currently no evidence of public proof-of-concept exploit code or active in-the-wild exploitation for CVE-2026-58236. The EPSS score is approximately 0.377%, indicating a low near-term exploitation probability. The NVD SSVC assessment classifies exploitation as "none" and the technical impact as "partial." The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and no threat actor attribution has been reported (GitHub Advisory, SAP Note).

軽減策と回避策

SAP has addressed this vulnerability as part of its August 2026 Security Patch Day. Organizations should apply the relevant SAP Security Note 3745182 via the SAP Support Portal to obtain the patched kernel versions. As an interim measure, restrict high-privilege access to SAP NetWeaver AS ABAP systems to only trusted administrators, and monitor system audit logs for suspicious OS command execution attempts. Refer to the SAP Security Patch Day page for the full list of affected kernel versions and corresponding patches (SAP Note, SAP Patch Day).

コミュニティの反応

Security firms covering SAP's August 2026 Patch Day, including Onapsis, SecurityBridge, and RedRays, published blog posts summarizing the monthly advisories, which included CVE-2026-58236 among other vulnerabilities. CyberSecurityNews and Cryptika also covered the broader SAP August 2026 patch release, noting vulnerabilities allowing malicious code injection. No specific high-profile researcher commentary or significant social media discussion focused exclusively on this CVE has been identified (Onapsis Blog, SecurityBridge Blog, RedRays Blog).

関連情報


ソース: このレポートは AI を使用して生成されました

関連 SAP NetWeaver Application Server ABAP 脆弱 性:

CVE 識別子

重大度

スコア

テクノロジー

コンポーネント名

CISA KEV エクスプロイト

修正あり

公開日

CVE-2026-44756CRITICAL10
  • SAP NetWeaver Application Server ABAP logoSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
いいえはいSep 08, 2026
CVE-2026-58240CRITICAL9.8
  • SAP NetWeaver Application Server ABAP logoSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
いいえはいSep 08, 2026
CVE-2026-66767HIGH7.7
  • SAP NetWeaver Application Server ABAP logoSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
いいえはいSep 08, 2026
CVE-2026-66779MEDIUM6.3
  • SAP NetWeaver Application Server ABAP logoSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
いいえいいえAug 11, 2026
CVE-2026-58236MEDIUM5.5
  • SAP NetWeaver Application Server ABAP logoSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
いいえはいAug 11, 2026

無料の脆弱性評価

クラウドセキュリティポスチャーのベンチマーク

9つのセキュリティドメインにわたるクラウドセキュリティプラクティスを評価して、リスクレベルをベンチマークし、防御のギャップを特定します。

評価を依頼する

パーソナライズされたデモを見る

実際に Wiz を見てみませんか?​

"私が今まで見た中で最高のユーザーエクスペリエンスは、クラウドワークロードを完全に可視化します。"
デビッド・エストリックCISO (最高情報責任者)
"Wiz を使えば、クラウド環境で何が起こっているかを 1 つの画面で確認することができます"
アダム・フレッチャーチーフ・セキュリティ・オフィサー
"Wizが何かを重要視した場合、それは実際に重要であることを私たちは知っています。"
グレッグ・ポニャトフスキ脅威および脆弱性管理責任者