
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-0509 is a missing authorization vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform that allows an authenticated, low-privileged user to perform background Remote Function Calls (RFCs) without the required S_RFC authorization in certain cases. The vulnerability was published on February 10, 2026, coinciding with SAP's February 2026 Security Patch Day. Affected components include SAP NetWeaver AS ABAP Kernel versions 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 9.16, 9.18, and 9.19, as well as KRNL64NUC and KRNL64UC variants (versions 7.22, 7.22ext, 7.53). It carries a CVSS v3.1 base score of 9.6 (Critical) (SAP Security Notes, Red Hat CVE).
The root cause is classified as CWE-862 (Missing Authorization) — the application fails to enforce the S_RFC authorization check when processing certain background RFC requests, allowing low-privileged authenticated users to invoke RFC-enabled function modules that should be restricted. The attack vector is network-based, requires no user interaction, and only low privileges (a valid SAP user account) are needed to trigger the flaw. Because the scope is changed, a successful exploit can affect resources beyond the immediate vulnerable component, enabling an attacker to interact with backend systems or other connected SAP components via unauthorized RFC calls (Red Hat CVE, Onapsis Blog).
Successful exploitation results in high impact on both integrity and availability, with no impact on confidentiality. An attacker with a low-privileged SAP account could execute background RFCs to modify critical system configurations, corrupt data, or disrupt business-critical operations across networked SAP systems. The changed scope means the impact can extend beyond the directly vulnerable system to other SAP components or connected backend systems, increasing the risk of cascading disruption in enterprise environments (Red Hat CVE, Onapsis Blog).
As of the time of reporting, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Red Hat CVE). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.036%, indicating a currently low probability of exploitation in the near term. No threat actor attribution has been reported in connection with this CVE (Onapsis Blog).
SAP released patches for CVE-2026-0509 as part of the February 2026 SAP Security Patch Day. Organizations should apply the relevant SAP Security Notes immediately for all affected kernel versions (7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 9.16, 9.18, 9.19 and associated KRNL64NUC/KRNL64UC variants) via the SAP Support Portal. As an interim measure, administrators should review and tighten S_RFC authorization assignments for all low-privileged accounts, enforcing the principle of least privilege, and monitor RFC activity for anomalous patterns (SAP Security Notes, Onapsis Blog).
The vulnerability was covered as part of broader SAP February 2026 Patch Day reporting by multiple security outlets. Onapsis highlighted it among the notable fixes in their monthly SAP patch day analysis, and SecurityBridge also covered it in their February 2026 patch day blog (Onapsis Blog, SecurityBridge). The Canadian Centre for Cyber Security issued an advisory covering the February 2026 SAP security updates (CCCS Advisory). The Hacker News and GBHackers also reported on the broader SAP patch day, noting the critical severity of several fixes released alongside this CVE (The Hacker News).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."