Advisory
On 13.01.2026 a security relevant correction has been released by SAP SE. The manufacturer resolves an issue within Kernel.
SAP Note 3675151 addresses "[CVE-2026-0507] OS Command Injection vulnerability in SAP Application Server for ABAP and SAP NetWeaver RFCSDK" to prevent code injection with a high risk for exploitation.
A workaround does not exist, according to SAP Security Advisory team. It is advisable to implement the correction as monthly patch process, the team suggests.
Risk specification
SAP Application Server for ABAP and SAP NetWeaver RFCSDK allow an authenticated attacker with administrative privileges and adjacent network access to upload specially crafted content, potentially resulting in arbitrary operating system command execution and full compromise of the host system.
Solution
Input validation has been enhanced to prevent unauthorized operating system command execution via specially crafted RFC requests.
The advisory is valid for
- KERNEL 7.53 55
- KERNEL 7.54 34
- KERNEL 7.77 51
- KERNEL 7.89 34
- KERNEL 7.93 28
- KERNEL 9.16 6
- KRNL64UC 7.53 55
- NWRFCSDK 7.50
