CVE-2026-0488

Severity
9.9CRITICAL
EPSS
0.0%
top 94.83%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 10

Description

An authenticated attacker in SAP CRM and SAP S/4HANA (Scripting Editor) could exploit a flaw in a generic function module call and execute unauthorized critical functionalities, which includes the ability to execute an arbitrary SQL statement. This leads to a full database compromise with high impact on confidentiality, integrity, and availability.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:HExploitability: 3.1 | Impact: 6.0

Affected Packages4 packages

🔴Vulnerability Details

2
GHSA
GHSA-rj9r-f39x-h33w: An authenticated attacker in SAP CRM and SAP S/4HANA (Scripting Editor) could exploit a flaw in a generic function module call and execute unauthorize2026-02-10
CVEList
Code Injection vulnerability in SAP CRM and SAP S/4HANA (Scripting Editor)2026-02-10

🕵️Threat Intelligence

1
Wiz
CVE-2026-0488 Impact, Exploitability, and Mitigation Steps | Wiz
CVE-2026-0488 (CRITICAL CVSS 9.9) | An authenticated attacker in SAP CR | cvebase.io