Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4355 articles · 196337 vulns · 36/41 feeds (7d)
← Back to list
8.8
CVE-2026-58243
sap · sap abap developer tools

Privilege Escalation vulnerability in SAP ABAP Developer Tools

Description

SAP ABAP Development Tools does not perform necessary authorization checks for certain functionality, allowing an attacker with low privileges to execute unauthorized database operations against SAP NetWeaver AS ABAP. Successful exploitation could allow the attacker to read sensitive data, modify application data, and disrupt access for legitimate users, resulting in high impact on confidentiality, integrity, and availability.

Affected Products

VendorProductVersions
sapsap abap developer toolsSAP_BASIS 750, SAP_BASIS 751, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758, SAP_BASIS 816, SAP_BASIS 918, SAP_BASIS 920

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
sapsap softwarecert_advisory90%

References

  • https://me.sap.com/notes/3772411
  • https://url.sap/sapsecuritypatchday

Related News (3 articles)

Tier B
BSI Advisories12d ago
[NEU] [hoch] SAP Patch Day August 2026: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
VulDB13d ago
CVE-2026-58243 | SAP ABAP Developer Tools SAP_BASIS 750 up to SAP_BASIS 918 privileges management
→ No new info (linked only)
Tier B
CERT-FR13d ago
Multiples vulnérabilités dans les produits SAP (11 août 2026)
→ No new info (linked only)
CVSS 3.18.8 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
CWECWE-862
PublishedAug 11, 2026
Trending Score11
Source articles3
Independent3
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-58231EXPKEV
Improper Authorization in SAP Commerce Cloud (Data Hub Adapter)
Trending: 55
CRITICALCVE-2026-34265
Memory Corruption vulnerability in Application Server ABAP for SAP NetWeaver and ABAP Platform
Trending: 17
CRITICALCVE-2026-44758
Code Injection vulnerability in Manufacturing Integration and Intelligence
Trending: 14
HIGHCVE-2026-44764
Missing Authorization Check in SAP Manufacturing Integration and Intelligence
Trending: 13
HIGHCVE-2026-44765
Missing Authorization Check in SAP Manufacturing Integration and Intelligence
Trending: 13

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 11, 2026
Discovered by ZDM
Aug 11, 2026