Advisory
On 11.08.2026 a security relevant correction has been released by SAP SE. The manufacturer resolves an issue within Kernel / ABAP.
SAP Note 3745182 addresses "3745182 - [CVE-2026-58236] OS Command Injection vulnerability in Application Server ABAP of SAP NetWeaver and ABAP Platform" to prevent os command injection with a medium risk for exploitation.
A workaround does not exist, according to SAP Security Advisory team. It is advisable to implement the correction as part of maintenance, the team suggests.
Risk specification
SAP NetWeaver Application Server ABAP and ABAP Platform allow an authenticated attacker with high privileges to exploit the absence of security controls on an internal code path and execute operating system commands that write to the operating system or stop the SAP system, resulting in unauthorized modification of system data or service disruption.
Solution
Access to operating system command execution is now more strictly controlled.
The advisory is valid for
- KRNL64NUC 7.22 45
- KRNL64NUC 7.22EXT 45
- KRNL64UC 7.22 45
- KRNL64UC 7.22EXT 45
- KRNL64UC 7.53 62
- KERNEL 7.22 39
- KERNEL 7.53 62
- KERNEL 7.77 58
- KERNEL 7.54 41
- KERNEL 7.93 34
- KERNEL 9.16 12
