Wiz가 Google Cloud에 합류: 함께 마법을 만드는 것

CVE-2026-58236
SAP NetWeaver Application Server ABAP 취약성 분석 및 완화

개요

CVE-2026-58236 is an OS command injection vulnerability (CWE-78) in SAP NetWeaver Application Server ABAP and ABAP Platform that allows a high-privileged attacker to bypass missing security controls on an internal code path, leading to operating system command execution. It was published on August 11, 2026, as part of SAP's Security Patch Day. Affected kernel versions include KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.53, KERNEL 7.22, 7.54, 7.77, 7.93, and 9.16. The vulnerability carries a CVSS v3.1 base score of 5.5 (Medium) (GitHub Advisory, SAP Note).

기술적 세부 사항

The root cause is classified as CWE-78 (Improper Neutralization of Special Elements used in an OS Command), where SAP NetWeaver AS ABAP fails to properly sanitize input on an internal code path, allowing injected OS commands to be passed to the underlying operating system. The attack vector is network-based with low complexity, but exploitation requires high privileges — meaning the attacker must already hold elevated access within the SAP system. The vulnerability bypasses missing security controls on a specific internal code path rather than exploiting an externally exposed interface directly. No public proof-of-concept code or detailed technical write-ups have been identified at this time (GitHub Advisory, SAP Note).

영향

Successful exploitation results in no confidentiality impact, low integrity impact, and high availability impact. An attacker with high privileges can execute arbitrary OS-level commands that write to the operating system or stop the SAP system entirely, causing significant service disruption. While data exfiltration is not a direct consequence, the ability to halt the SAP system poses a serious operational risk for organizations relying on SAP for critical business processes (GitHub Advisory).

악용 가능성

There is currently no evidence of public proof-of-concept exploit code or active in-the-wild exploitation for CVE-2026-58236. The EPSS score is approximately 0.377%, indicating a low near-term exploitation probability. The NVD SSVC assessment classifies exploitation as "none" and the technical impact as "partial." The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and no threat actor attribution has been reported (GitHub Advisory, SAP Note).

완화 및 해결 방법

SAP has addressed this vulnerability as part of its August 2026 Security Patch Day. Organizations should apply the relevant SAP Security Note 3745182 via the SAP Support Portal to obtain the patched kernel versions. As an interim measure, restrict high-privilege access to SAP NetWeaver AS ABAP systems to only trusted administrators, and monitor system audit logs for suspicious OS command execution attempts. Refer to the SAP Security Patch Day page for the full list of affected kernel versions and corresponding patches (SAP Note, SAP Patch Day).

커뮤니티 반응

Security firms covering SAP's August 2026 Patch Day, including Onapsis, SecurityBridge, and RedRays, published blog posts summarizing the monthly advisories, which included CVE-2026-58236 among other vulnerabilities. CyberSecurityNews and Cryptika also covered the broader SAP August 2026 patch release, noting vulnerabilities allowing malicious code injection. No specific high-profile researcher commentary or significant social media discussion focused exclusively on this CVE has been identified (Onapsis Blog, SecurityBridge Blog, RedRays Blog).

추가 자료


근원이 보고서는 AI를 사용하여 생성되었습니다.

관련 SAP NetWeaver Application Server ABAP 취약점:

CVE ID

심각도

점수

기술

구성 요소 이름

CISA KEV 익스플로잇

수정 사항이 있습니다.

게시된 날짜

CVE-2026-44756CRITICAL10
  • SAP NetWeaver Application Server ABAP logoSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
아니요Sep 08, 2026
CVE-2026-58240CRITICAL9.8
  • SAP NetWeaver Application Server ABAP logoSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_java
아니요아니요Sep 08, 2026
CVE-2026-66767HIGH7.7
  • SAP NetWeaver Application Server ABAP logoSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
아니요Sep 08, 2026
CVE-2026-66779MEDIUM6.3
  • SAP NetWeaver Application Server ABAP logoSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
아니요아니요Aug 11, 2026
CVE-2026-58236MEDIUM5.5
  • SAP NetWeaver Application Server ABAP logoSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
아니요Aug 11, 2026

무료 취약성 평가

클라우드 보안 태세를 벤치마킹합니다

9개의 보안 도메인에서 클라우드 보안 관행을 평가하여 위험 수준을 벤치마킹하고 방어의 허점을 식별합니다.

평가 요청

추가 Wiz 리소스

맞춤형 데모 받기

맞춤형 데모 신청하기

"내가 본 최고의 사용자 경험은 클라우드 워크로드에 대한 완전한 가시성을 제공합니다."
데이비드 에슬릭최고정보책임자(CISO)
"Wiz는 클라우드 환경에서 무슨 일이 일어나고 있는지 볼 수 있는 단일 창을 제공합니다."
아담 플레처최고 보안 책임자(CSO)
"우리는 Wiz가 무언가를 중요한 것으로 식별하면 실제로 중요하다는 것을 알고 있습니다."
그렉 포니아토프스키위협 및 취약성 관리 책임자