Advisory
SAP takes the security of its vast product portfolio very seriously and thus releases security fixes for
vulnerabilities reported by external researchers and their customers every second Tuesday of the month.
SAP Note 3773304
was released on
14.07.2026 and deals with
"3773304 - [CVE-2026-58233] Remote Code Execution vulnerability in SAP Change and Transport System Attach Tool (ctsattach)" within SAP Change and Transport System.
We advice you to follow the instructions, to resolve
remote code execution vulnerability
with a
high potential for exploitation
in component BC-CTS-TMS-PLS.
According to SAP Security Advisory team a workaround does not exist. It is advisable to implement the correction as monthly patch process.
Risk specification
SAP Change and Transport System Attach Tool (ctsattach) allows an authenticated attacker to supply a specially crafted archive file that, when processed by a victim, triggers insecure deserialization. This may result in remote code execution, enabling the extraction of sensitive data and the compromise of system processes.
Solution
The ctsattach tool has been discontinued in accordance with the SAP Developer License Agreement 3.2.
The advisory is valid for
- CTS_UPLOAD_CLT 1
