SAP S/4HANA (Private Cloud and On-Premise) allows an attacker with admin privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injection of arbitrary ABAP code/OS commands into the system, bypassing essential authorization checks. This vulnerability effectively functions as a backdoor, creating the risk of full system compromise, undermining the confidentiality, integrity and availability of the system.
References
| Link | Resource |
|---|---|
| https://me.sap.com/notes/3694242 | Permissions Required |
| https://url.sap/sapsecuritypatchday | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
22 Jan 2026, 18:44
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://me.sap.com/notes/3694242 - Permissions Required | |
| References | () https://url.sap/sapsecuritypatchday - Patch, Vendor Advisory | |
| CPE | cpe:2.3:a:sap:s\/4_hana:108:*:*:*:*:*:*:* cpe:2.3:a:sap:s\/4_hana:104:*:*:*:*:*:*:* cpe:2.3:a:sap:s\/4_hana:109:*:*:*:*:*:*:* cpe:2.3:a:sap:s\/4_hana:106:*:*:*:*:*:*:* cpe:2.3:a:sap:s\/4_hana:102:*:*:*:*:*:*:* cpe:2.3:a:sap:s\/4_hana:103:*:*:*:*:*:*:* cpe:2.3:a:sap:s\/4_hana:107:*:*:*:*:*:*:* cpe:2.3:a:sap:s\/4_hana:105:*:*:*:*:*:*:* |
|
| First Time |
Sap s\/4 Hana
Sap |
13 Jan 2026, 02:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-13 02:15
Updated : 2026-01-22 18:44
NVD link : CVE-2026-0498
Mitre link : CVE-2026-0498
CVE.ORG link : CVE-2026-0498
JSON object : View
Products Affected
sap
- s\/4_hana
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')
