
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-0506 is a Missing Authorization Check vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform that allows authenticated attackers to misuse RFC (Remote Function Call) functions to execute ABAP form routines (FORMs) without proper authorization. The vulnerability was disclosed on January 12–13, 2026, and affects SAP_BASIS versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 758, and 816. It carries a CVSS v3.1 base score of 8.1 (High), assigned by SAP SE (SAP Patch Day, SAP Note).
The root cause is classified as CWE-862 (Missing Authorization), where the ABAP application server fails to enforce proper authorization checks before allowing RFC-callable functions to invoke FORM routines. An authenticated attacker with low-privilege network access can craft RFC calls targeting exposed FORMs, bypassing the expected authorization validation layer. No user interaction is required, and the attack complexity is low, making it straightforward to exploit once valid credentials are obtained. No public technical write-ups or proof-of-concept code have been identified at this time (SAP Patch Day, SAP Note).
Successful exploitation allows an attacker to write or modify data accessible through ABAP FORMs and invoke system functionality exposed via those FORMs, resulting in high impact on both integrity and availability. Confidentiality is not affected by this vulnerability. Given the broad version range affected — spanning over two decades of SAP_BASIS releases — the potential scope is significant across enterprise SAP landscapes, and abuse of FORM routines could disrupt critical business processes or corrupt application data (SAP Patch Day, Feedly).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of this report. The EPSS score is approximately 0.036%, indicating a low current probability of exploitation in the wild. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (Feedly).
SAP released patches on January 22, 2026, as part of SAP Security Patch Day (January 2026); organizations should apply SAP Security Note 3688703 to all affected SAP_BASIS versions (700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 758, 816). As interim mitigations, administrators should implement network-level access controls to restrict RFC function usage to trusted hosts and users, review and enforce proper authorization objects on all RFC-callable FORM routines, and restrict system access to users with appropriate privilege levels. Monitoring RFC function calls for unauthorized FORM execution attempts via SAP Security Audit Log is also recommended (SAP Patch Day, SAP Note).
The vulnerability was covered as part of SAP's January 2026 Security Patch Day, which addressed 17 security notes in total. Security outlets including CyberSecurityNews, GBHackers, SecurityBridge, and RedRays published summaries of the January 2026 SAP patch day, noting the RFC authorization bypass among the notable fixes. Social media activity on Mastodon and Bluesky reflected routine community awareness of the SAP patch cycle, with no extraordinary alarm raised specifically for this CVE (SecurityBridge, RedRays, CyberSecurityNews).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."