Advisory
SAP takes the security of its vast product portfolio very seriously and thus releases security fixes for
vulnerabilities reported by external researchers and their customers every second Tuesday of the month.
SAP Note 3773304
was released on
14.07.2026 and deals with
"3773304 - [CVE-2026-58233] Remote Code Execution vulnerability in Enhanced Change and Transport System (CTS+) Attach Tool (ctsattach)" within SAP Change and Transport System.
We advice you to follow the instructions, to resolve
remote code execution vulnerability
with a
high potential for exploitation
in component BC-CTS-TMS-PLS.
According to SAP Security Advisory team a workaround does not exist. It is advisable to implement the correction as monthly patch process.
Risk specification
This note has been re-released with updated 'Title', 'Other Terms', 'Reason and Prerequisites', and 'Solution' sections. Enhanced Change and Transport System (CTS+) attach tool (ctsattach) allows an authenticated attacker to supply a specially crafted archive file that, when processed by a victim, triggers insecure deserialization leading to remote code execution, resulting in the extraction of sensitive data and compromise of system processes.
Solution
The 'ctsattach' tool has been discontinued in accordance with the SAP Developer License Agreement 3.2.
The advisory is valid for
- CTS_UPLOAD_CLT 1
