
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-0498 is a code injection vulnerability in SAP S/4HANA (Private Cloud and On-Premise) that allows an attacker with admin privileges to inject arbitrary ABAP code and OS commands via a function module exposed through RFC (Remote Function Call), effectively creating a backdoor. The vulnerability affects SAP S/4HANA versions 102 through 109 (S4CORE 102–109). It was published on January 12–13, 2026, with patches made available on January 22, 2026. CVSS v3.1 scores differ by source: NVD rates it 7.2 (High) while SAP SE rates it 9.1 (Critical) due to a broader scope assessment (SAP Security Patch Day, Red Hat CVE).
The root cause is classified as CWE-94 (Improper Control of Generation of Code / Code Injection). The vulnerability resides in a function module exposed via RFC in SAP S/4HANA, where insufficient input validation and missing authorization checks allow injected ABAP code or OS commands to be executed on the underlying system. An attacker must have admin-level privileges and network access to the RFC endpoint, but no user interaction is required. The flaw bypasses essential authorization checks, functioning as a persistent backdoor (SAP Security Note 3694242, RedRays Blog).
Successful exploitation results in full system compromise, with high impact to confidentiality, integrity, and availability. An attacker can read or exfiltrate sensitive business data (financial records, HR data, supply chain information), modify or delete data, execute arbitrary OS commands on the underlying server, and potentially disrupt or shut down the SAP system entirely. Given SAP S/4HANA's role as a core enterprise ERP platform, compromise could enable lateral movement across connected business systems and supply chain partners (Red Hat CVE, RedRays Blog).
rfcexec, or custom RFC client libraries (e.g., PyRFC or SAP JCo) authenticated with the obtained admin credentials.<sid>adm or SAP service account; new scheduled jobs (SM36/SM37) created without corresponding change requests (RedRays Blog, SAP Security Patch Day).SAP released patches on January 22, 2026, as part of the January 2026 SAP Security Patch Day; organizations should apply SAP Security Note 3694242 immediately to all affected S/4HANA instances (versions 102–109). As interim mitigations, restrict network access to RFC endpoints (TCP 3300+) to trusted networks only, enforce strict admin privilege controls using the principle of least privilege, and implement additional authorization object checks on RFC-exposed function modules. Monitor RFC function module activity for anomalous patterns and review recent admin activity logs for signs of compromise (SAP Security Patch Day, SAP Security Note 3694242, SAP January 2026 Notes).
The vulnerability received notable coverage across the SAP security community following the January 2026 Patch Day. RedRays published a dedicated technical blog post characterizing the flaw as a backdoor and highlighting its severity (RedRays Blog). SecurityBridge and CyberSecurityNews also covered the January 2026 SAP Patch Day, noting this as one of the more critical issues addressed (SecurityBridge, CyberSecurityNews). The Hacker News included it in their weekly recap, and social media discussion appeared on Mastodon and Bluesky, reflecting broad awareness in the enterprise security community (The Hacker News).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."