CVE-2026-0498Disclosure(sap / s\/4_hana)

LOWCVSS 7.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch sap s\/4_hana systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

SAP S/4HANA (Private Cloud and On-Premise) allows an attacker with admin privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injection of arbitrary ABAP code/OS commands into the system, bypassing essential authorization checks. This vulnerability effectively functions as a backdoor, creating the risk of full system compromise, undermining the confidentiality, integrity and availability of the system.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • s\/4_hana

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
s\/4_hana

8 versions affected across 1 product

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-05-13: 1Patch / Workaround · 2026-05-13: 1Technical Details · 2026-05-13: 105-13
Signal classification1 categories
Disclosure
1100.0%
Referenced assets5 URLs
Full discourse1 post
  • にゃん☆たく/takumi.a@taku888infinity
    Disclosure

    2026年5月ぱっちちゅーずでーまとめ ◆Microsoft https://www.microsoft.com/en-us/msrc/blog/2026/05/202605-security-update CVE-2026-42898 Microsoft Dynamics 365 オンプレミスのリモートでコードが実行される脆弱性 CVE-2026-42823 Azure Logic Apps の特権昇格の脆弱性 CVE-2026-41096 Windows DNS クライアントのリモートでコードが実行される脆弱性 CVE-2026-41089 Windows Netlogon のリモートでコードが実行される脆弱性 ◆Ivanti https://www.ivanti.com/blog/may-2026-security-update critical1件 ■CVE-2026-8043(Critical) ファイル名制御不備により認証済ユーザが任意ファイル読取・HTML書込可能。情報漏えいに加え、XSS等のクライアント攻撃や踏み台化の恐れ ◆Fortinet https://fortiguard.fortinet.com/psirt critical2件 ■CVE-2026-26083(FortiSandbox / 認証不要RCE) 認可不備により未認証攻撃者がHTTPリクエスト経由で任意コード実行可能。ネットワーク越し・認証不要で悪用可能なため侵害難易度が低く、最優先でのパッチ適用が必要。 ■CVE-2026-44277(FortiAuthenticator / 認証不要RCE) APIのアクセス制御不備により未認証攻撃者が任意コマンド実行可能。IAM基盤への侵害に直結し、認証・証明書管理を含む全体統制を破壊するリスクが高い。 ◆SAP SAP Security Patch Day - January 2026 https://support.sap.com/en/my-support/knowledge-base/security-notes-news/january-2026.html critical4件 ■ CVE-2026-0501(SQL Injection:S/4HANA) 外部入力の検証不備によりSQLインジェクションが成立し、DBの機密情報取得・改ざん・削除が可能。業務データへの直接影響が大きい。認証済ユーザ(業務ユーザ等)でも悪用可能なケースが想定され、権限逸脱型リスクが高い。 ■ CVE-2026-0500(RCE:Wily Introscope) 細工されたリクエストにより任意コード実行が可能となる脆弱性。監視基盤の乗っ取りや横展開の踏み台となる危険がある。認証不要または低権限でも悪用できる可能性があり、外部攻撃者・内部第三者双方に対して高リスク。 ■ CVE-2026-0498(Code Injection:S/4HANA) 入力処理不備を突いたコードインジェクションにより、アプリケーション処理の改ざんや不正実行が可能。業務アプリ経由で実行されるため、正規ユーザ(認証済第三者)による悪用や、意図しない権限範囲での操作に繋がるリスクが高い。 ■ CVE-2026-0491(Code Injection:Landscape Transformation) データ移行・統合処理におけるコードインジェクションにより、システム改ざんやデータ破壊が可能。移行作業や連携処理を扱う認証済ユーザから悪用される可能性があり、内部・委託先など第三者経由での被害拡大が懸念。 ◆Adobe https://helpx.adobe.com/security.html critical4件 ■CVE-2026-34659(Adobe Connect / RCE) デシリアライズ不備により未認証攻撃者が細工データを通じて任意コード実行可能。ユーザ操作誘導で成立し、CVSS9.6の極めて高リスク脆弱性。 ■CVE-2026-34660(Adobe Connect / 権限昇格) 認可不備により権限昇格が可能。RCEと組み合わせることで完全な環境乗っ取りに発展する恐れがあり、Connect系の中でも特に影響大。 ■CVE-2026-34653(Adobe Commerce / パストラバーサル) ディレクトリ操作不備により任意ファイル書込みが可能。攻撃者によるサーバ改ざん・Webシェル設置に繋がる恐れがある重大リスク。 ■CVE-2026-34686(Adobe Commerce / XSS→RCE) 保存型XSSにより任意スクリプト実行が可能。管理画面等と組み合わせるとコード実行やセッション奪取等の高リスク攻撃に発展。

    Post summary

    The text is a vendor‑summarized disclosure of multiple critical CVEs, detailing exploit types, impact, and patch urgency, but it does not mention any PoC, active exploitation, or false‑positive claims.

    000211.4K
    11.7K followersView on X
CPE platform detail8 entries

8 of 8 entries

PartVendorProductVersionTarget SWTarget HW
Appsaps\/4_hana102--
Appsaps\/4_hana103--
Appsaps\/4_hana104--
Appsaps\/4_hana105--
Appsaps\/4_hana106--
Appsaps\/4_hana107--
Appsaps\/4_hana108--
Appsaps\/4_hana109--

Explore more