cbcvebase.
CVE-2026-0484
published 2026-02-10

CVE-2026-0484: Due to missing authorization check in SAP NetWeaver Application Server ABAP and SAP S/4HANA, an authenticated attacker could access a specific transaction code…

PriorityP341medium6.5CVSS 3.1
AVNACLPRLUINSUCNIHAN
EPSS
0.27%
18.7th percentile
Due to missing authorization check in SAP NetWeaver Application Server ABAP and SAP S/4HANA, an authenticated attacker could access a specific transaction code and modify the text data in the system. This vulnerability has a high impact on integrity of the application with no effect on the confidentiality and availability.

Affected

30 ranges· showing 25
VendorProductVersion rangeFixed in
sapsap_basis
sapsap_basis
sapsap_basis
sapsap_basis
sapsap_basis
sapsap_basis
sapsap_basis
sapsap_basis
sapsap_basis
sapsap_basis
sapsap_basis
sapsap_basis
sapsap_basis
sapsap_basis
sapsap_basis
sap_sesap_netweaver_application_server_abap_and_sap_s_4hana
sap_sesap_netweaver_application_server_abap_and_sap_s_4hana
sap_sesap_netweaver_application_server_abap_and_sap_s_4hana
sap_sesap_netweaver_application_server_abap_and_sap_s_4hana
sap_sesap_netweaver_application_server_abap_and_sap_s_4hana
sap_sesap_netweaver_application_server_abap_and_sap_s_4hana
sap_sesap_netweaver_application_server_abap_and_sap_s_4hana
sap_sesap_netweaver_application_server_abap_and_sap_s_4hana
sap_sesap_netweaver_application_server_abap_and_sap_s_4hana
sap_sesap_netweaver_application_server_abap_and_sap_s_4hana
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.