CVE-2026-58236
SAP NetWeaver Application Server ABAP Análise e mitigação de vulnerabilidades

Visão geral

CVE-2026-58236 is an OS command injection vulnerability (CWE-78) in SAP NetWeaver Application Server ABAP and ABAP Platform that allows a high-privileged attacker to bypass missing security controls on an internal code path, leading to operating system command execution. It was published on August 11, 2026, as part of SAP's Security Patch Day. Affected kernel versions include KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.53, KERNEL 7.22, 7.54, 7.77, 7.93, and 9.16. The vulnerability carries a CVSS v3.1 base score of 5.5 (Medium) (GitHub Advisory, SAP Note).

Detalhes técnicos

The root cause is classified as CWE-78 (Improper Neutralization of Special Elements used in an OS Command), where SAP NetWeaver AS ABAP fails to properly sanitize input on an internal code path, allowing injected OS commands to be passed to the underlying operating system. The attack vector is network-based with low complexity, but exploitation requires high privileges — meaning the attacker must already hold elevated access within the SAP system. The vulnerability bypasses missing security controls on a specific internal code path rather than exploiting an externally exposed interface directly. No public proof-of-concept code or detailed technical write-ups have been identified at this time (GitHub Advisory, SAP Note).

Impacto

Successful exploitation results in no confidentiality impact, low integrity impact, and high availability impact. An attacker with high privileges can execute arbitrary OS-level commands that write to the operating system or stop the SAP system entirely, causing significant service disruption. While data exfiltration is not a direct consequence, the ability to halt the SAP system poses a serious operational risk for organizations relying on SAP for critical business processes (GitHub Advisory).

Exploração

There is currently no evidence of public proof-of-concept exploit code or active in-the-wild exploitation for CVE-2026-58236. The EPSS score is approximately 0.377%, indicating a low near-term exploitation probability. The NVD SSVC assessment classifies exploitation as "none" and the technical impact as "partial." The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and no threat actor attribution has been reported (GitHub Advisory, SAP Note).

Mitigação e soluções alternativas

SAP has addressed this vulnerability as part of its August 2026 Security Patch Day. Organizations should apply the relevant SAP Security Note 3745182 via the SAP Support Portal to obtain the patched kernel versions. As an interim measure, restrict high-privilege access to SAP NetWeaver AS ABAP systems to only trusted administrators, and monitor system audit logs for suspicious OS command execution attempts. Refer to the SAP Security Patch Day page for the full list of affected kernel versions and corresponding patches (SAP Note, SAP Patch Day).

Reações da comunidade

Security firms covering SAP's August 2026 Patch Day, including Onapsis, SecurityBridge, and RedRays, published blog posts summarizing the monthly advisories, which included CVE-2026-58236 among other vulnerabilities. CyberSecurityNews and Cryptika also covered the broader SAP August 2026 patch release, noting vulnerabilities allowing malicious code injection. No specific high-profile researcher commentary or significant social media discussion focused exclusively on this CVE has been identified (Onapsis Blog, SecurityBridge Blog, RedRays Blog).

Recursos adicionais


OrigemEste relatório foi gerado usando IA

Relacionado SAP NetWeaver Application Server ABAP Vulnerabilidades:

CVE ID

Gravidade

Pontuação

Tecnologias

Nome do componente

Exploração do CISA KEV

Tem correção

Data de publicação

CVE-2026-44756CRITICAL10
  • SAP NetWeaver Application Server ABAP logoSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
NãoSimSep 08, 2026
CVE-2026-58240CRITICAL9.8
  • SAP NetWeaver Application Server ABAP logoSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
NãoNãoSep 08, 2026
CVE-2026-66767HIGH7.7
  • SAP NetWeaver Application Server ABAP logoSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
NãoSimSep 08, 2026
CVE-2026-66779MEDIUM6.3
  • SAP NetWeaver Application Server ABAP logoSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
NãoNãoAug 11, 2026
CVE-2026-58236MEDIUM5.5
  • SAP NetWeaver Application Server ABAP logoSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
NãoSimAug 11, 2026

Avaliação de vulnerabilidade gratuita

Compare sua postura de segurança na nuvem

Avalie suas práticas de segurança na nuvem em 9 domínios de segurança para comparar seu nível de risco e identificar lacunas em suas defesas.

Solicitar avaliação

Marque uma demonstração personalizada

Pronto para ver a Wiz em ação?

"A melhor experiência do usuário que eu já vi, fornece visibilidade total para cargas de trabalho na nuvem."
David EstlickCISO
"A Wiz fornece um único painel de vidro para ver o que está acontecendo em nossos ambientes de nuvem."
Adam FletcherDiretor de Segurança
"Sabemos que se a Wiz identifica algo como crítico, na verdade é."
Greg PoniatowskiChefe de Gerenciamento de Ameaças e Vulnerabilidades