CVE-2026-44751
SAP NetWeaver Application Server ABAP vulnerability analysis and mitigation

Overview

CVE-2026-44751 is a missing authorization vulnerability in SAP Application Server ABAP (NetWeaver and ABAP Platform) that allows authenticated low-privileged users to execute report generation commands and overwrite data belonging to other users, resulting in privilege escalation. It was published on June 9, 2026, and affects SAP_BASIS versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 758, and 816. The vulnerability carries a CVSS v3.1 base score of 7.1 (High) (GitHub Advisory, ENISA EUVD).

Technical details

The root cause is CWE-862 (Missing Authorization): the ABAP application server fails to perform necessary authorization checks before allowing an authenticated user to execute report generation commands. An attacker with low-privileged network access can invoke these commands over the network without user interaction, causing the server to process the request as if the attacker had broader permissions. This allows the attacker to overwrite report data or output belonging to other users, effectively escalating their privileges within the system. The SAP Security Note 3735546 addresses this flaw (GitHub Advisory, SAP Support).

Impact

Successful exploitation results in high integrity impact — an attacker can overwrite information belonging to other users — and low availability impact, with no confidentiality impact. The vulnerability enables privilege escalation within the SAP ABAP environment, potentially allowing a low-privileged user to manipulate business-critical reports or data owned by higher-privileged accounts. Given the broad version range affected (spanning SAP_BASIS 700 through 816), a large number of enterprise SAP deployments could be at risk (GitHub Advisory, Onapsis Blog).

Exploitation steps

  1. Reconnaissance: Identify SAP NetWeaver ABAP application servers running affected SAP_BASIS versions (700–816) using network scanning or SAP landscape discovery tools.
  2. Authentication: Obtain any valid low-privileged SAP user account (e.g., a standard business user or test account).
  3. Identify vulnerable report generation function: Locate ABAP report execution interfaces or transaction codes that invoke report generation commands without enforcing authorization object checks.
  4. Execute unauthorized report command: Submit a crafted request to the report generation function specifying another user's report output or data target, bypassing the missing authorization check.
  5. Overwrite target data: The server processes the command without validating the caller's permissions, overwriting the targeted user's report data or output, effectively escalating the attacker's effective privileges within the SAP system (GitHub Advisory).

Indicators of compromise

  • Logs: SAP system logs (SM21, SLG1) showing report execution transactions invoked by low-privileged users against data objects owned by other users; authorization check bypass events or missing authorization object entries in security audit logs (SM19/SM20).
  • Application: Unexpected modifications to report outputs or spool requests belonging to users other than the initiating user; unusual report execution patterns from accounts not typically running such reports.
  • Network: Authenticated HTTP/RFC requests to SAP ABAP application server endpoints triggering report generation functions from unexpected source IPs or user accounts.

Mitigation and workarounds

SAP has released a patch via SAP Security Note 3735546, published as part of the June 2026 SAP Security Patch Day. Organizations should apply this note immediately through the SAP Support Portal. As interim mitigations, administrators should review and restrict user authorizations to the minimum necessary, implement proper authorization object checks for report generation transactions, and monitor SAP security audit logs for anomalous report execution activity (SAP Support, SAP Patch Day, Onapsis Blog).

Community reactions

The vulnerability was covered as part of SAP's June 2026 Security Patch Day, which addressed multiple critical flaws across NetWeaver and Commerce Cloud. Security firms including Onapsis, RedRays, SecurityBridge, and SOCRadar published patch day summaries highlighting the broader set of June 2026 SAP vulnerabilities. BleepingComputer reported on the critical flaws fixed in this patch cycle, and CSOOnline noted the patch day as part of a broader trend of high-volume CVE releases (Onapsis Blog, BleepingComputer, SecurityBridge).

Additional resources


SourceThis report was generated using AI

Related SAP NetWeaver Application Server ABAP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-44747CRITICAL9.9
  • SAP NetWeaver Application Server ABAP logoSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
NoYesJul 14, 2026
CVE-2026-44748CRITICAL9.9
  • SAP NetWeaver Application Server ABAP logoSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
NoYesJun 09, 2026
CVE-2026-27671CRITICAL9.8
  • SAP NetWeaver Application Server ABAP logoSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
NoYesJun 09, 2026
CVE-2026-44751HIGH7.1
  • SAP NetWeaver Application Server ABAP logoSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
NoYesJun 09, 2026
CVE-2026-27680MEDIUM4.3
  • SAP NetWeaver Application Server ABAP logoSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
NoNoMay 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management