CVE-2026-0498

SAP S/4HANA (Private Cloud and On-Premise) allows an attacker with admin privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injection of arbitrary ABAP code/OS commands into the system, bypassing essential authorization checks. This vulnerability effectively functions as a backdoor, creating the risk of full system compromise, undermining the confidentiality, integrity and availability of the system.
References
Link Resource
https://me.sap.com/notes/3694242 Permissions Required
https://url.sap/sapsecuritypatchday Patch Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sap:s\/4_hana:102:*:*:*:*:*:*:*
cpe:2.3:a:sap:s\/4_hana:103:*:*:*:*:*:*:*
cpe:2.3:a:sap:s\/4_hana:104:*:*:*:*:*:*:*
cpe:2.3:a:sap:s\/4_hana:105:*:*:*:*:*:*:*
cpe:2.3:a:sap:s\/4_hana:106:*:*:*:*:*:*:*
cpe:2.3:a:sap:s\/4_hana:107:*:*:*:*:*:*:*
cpe:2.3:a:sap:s\/4_hana:108:*:*:*:*:*:*:*
cpe:2.3:a:sap:s\/4_hana:109:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-01-13 02:15

Updated : 2026-01-22 18:44


NVD link : CVE-2026-0498

Mitre link : CVE-2026-0498

CVE.ORG link : CVE-2026-0498


JSON object : View

Products Affected

sap

  • s\/4_hana
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')