CVE-2026-58246 MEDIUM

CVE-2026-58246: Information Disclosure vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform

Vendor Sap_Se
Product SAP NetWeaver Application Server for ABAP
Weakness CWE-497
Published July 28, 2026
Last update July 28, 2026

CVSS base score

4.3/10
Attack vector Adjacent
Attack complexity Low
Privileges required High
User interaction Required
Confidentiality High
Integrity None

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N

What the vulnerability does

01Description

SAP NetWeaver Application Server for ABAP and ABAP Platform writes sensitive session identifier information into a diagnostic trace when the trace is activated by a privileged user. An attacker with access to the resulting trace data could obtain identifiers that allow impersonation of legitimate users during their validity period. This leads to high impact on confidentiality. Integrity and availability are not impacted.

Key dates

02Disclosure timeline

July 28, 2026 CVE published
July 28, 2026 Record updated

Related vulnerabilities

04Related CVE