CVE-2026-0509
SAP NetWeaver Application Server ABAP vulnerability analysis and mitigation

Overview

CVE-2026-0509 is a missing authorization vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform that allows an authenticated, low-privileged user to perform background Remote Function Calls (RFCs) without the required S_RFC authorization in certain cases. The vulnerability was published on February 10, 2026, coinciding with SAP's February 2026 Security Patch Day. Affected components include SAP NetWeaver AS ABAP Kernel versions 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 9.16, 9.18, and 9.19, as well as KRNL64NUC and KRNL64UC variants (versions 7.22, 7.22ext, 7.53). It carries a CVSS v3.1 base score of 9.6 (Critical) (SAP Security Notes, Red Hat CVE).

Technical details

The root cause is classified as CWE-862 (Missing Authorization) — the application fails to enforce the S_RFC authorization check when processing certain background RFC requests, allowing low-privileged authenticated users to invoke RFC-enabled function modules that should be restricted. The attack vector is network-based, requires no user interaction, and only low privileges (a valid SAP user account) are needed to trigger the flaw. Because the scope is changed, a successful exploit can affect resources beyond the immediate vulnerable component, enabling an attacker to interact with backend systems or other connected SAP components via unauthorized RFC calls (Red Hat CVE, Onapsis Blog).

Impact

Successful exploitation results in high impact on both integrity and availability, with no impact on confidentiality. An attacker with a low-privileged SAP account could execute background RFCs to modify critical system configurations, corrupt data, or disrupt business-critical operations across networked SAP systems. The changed scope means the impact can extend beyond the directly vulnerable system to other SAP components or connected backend systems, increasing the risk of cascading disruption in enterprise environments (Red Hat CVE, Onapsis Blog).

Exploitability

As of the time of reporting, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Red Hat CVE). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.036%, indicating a currently low probability of exploitation in the near term. No threat actor attribution has been reported in connection with this CVE (Onapsis Blog).

Exploitation steps

  1. Reconnaissance: Identify SAP NetWeaver AS ABAP instances running vulnerable kernel versions (7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 9.16, 9.18, 9.19) using network scanning or SAP system landscape discovery tools.
  2. Obtain low-privileged credentials: Acquire any valid SAP user account — even a basic dialog or service account — through phishing, credential stuffing, or insider access.
  3. Identify target RFC function modules: Enumerate available RFC-enabled function modules that are normally restricted by S_RFC authorization, targeting those with high-impact operations (e.g., system configuration changes, batch job management).
  4. Invoke unauthorized background RFC: Exploit the missing authorization check by triggering a background RFC call to the target function module in a context where the S_RFC check is bypassed, using SAP GUI, RFC SDK, or custom ABAP programs.
  5. Achieve impact: Successfully execute the unauthorized RFC to modify system settings, manipulate data, or disrupt availability of the SAP application or connected systems (Red Hat CVE, Onapsis Blog).

Indicators of compromise

  • Logs: SAP system logs (SM21) showing RFC calls executed by low-privileged users to function modules they are not authorized for; Security Audit Log (SM20) entries for authorization failures followed by successful RFC executions from the same user in background processing context.
  • Process/Application: Unexpected background jobs (SM37) initiated by low-privileged user accounts invoking sensitive RFC-enabled function modules; unusual RFC connections in transaction SM59 or RFCMON originating from standard user accounts.
  • Network: Unusual RFC traffic (TCP port 3300/33xx) from internal hosts to SAP application servers initiated by accounts not typically performing RFC operations; unexpected RFC gateway connections logged in the SAP gateway monitor (SMGW).
  • Authorization: SAP authorization trace (ST01) showing S_RFC authorization checks being bypassed or not triggered for background RFC calls that would normally require explicit authorization (Onapsis Blog, Red Hat CVE).

Mitigation and workarounds

SAP released patches for CVE-2026-0509 as part of the February 2026 SAP Security Patch Day. Organizations should apply the relevant SAP Security Notes immediately for all affected kernel versions (7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 9.16, 9.18, 9.19 and associated KRNL64NUC/KRNL64UC variants) via the SAP Support Portal. As an interim measure, administrators should review and tighten S_RFC authorization assignments for all low-privileged accounts, enforcing the principle of least privilege, and monitor RFC activity for anomalous patterns (SAP Security Notes, Onapsis Blog).

Community reactions

The vulnerability was covered as part of broader SAP February 2026 Patch Day reporting by multiple security outlets. Onapsis highlighted it among the notable fixes in their monthly SAP patch day analysis, and SecurityBridge also covered it in their February 2026 patch day blog (Onapsis Blog, SecurityBridge). The Canadian Centre for Cyber Security issued an advisory covering the February 2026 SAP security updates (CCCS Advisory). The Hacker News and GBHackers also reported on the broader SAP patch day, noting the critical severity of several fixes released alongside this CVE (The Hacker News).

Additional resources


SourceThis report was generated using AI

Related SAP NetWeaver Application Server ABAP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-44747CRITICAL9.9
  • SAP NetWeaver Application Server ABAP logoSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
NoYesJul 14, 2026
CVE-2026-44748CRITICAL9.9
  • SAP NetWeaver Application Server ABAP logoSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
NoYesJun 09, 2026
CVE-2026-44751HIGH7.1
  • SAP NetWeaver Application Server ABAP logoSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
NoYesJun 09, 2026
CVE-2026-66779MEDIUM6.3
  • SAP NetWeaver Application Server ABAP logoSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
NoNoAug 11, 2026
CVE-2026-58236MEDIUM5.5
  • SAP NetWeaver Application Server ABAP logoSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
NoYesAug 11, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management