CVE-2026-24310Disclosure(sap / netweaver_application_server_abap)

LOWCVSS 4.3 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Due to missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker could execute specific ABAP function module and read the sensitive information from database catalog of the ABAP system. This vulnerability has low impact on the application's confidentiality with no effect on the integrity and availability.

0.0/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • netweaver_application_server_abap

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
netweaver_application_server_abap

13 versions affected across 1 product

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-03-10: 3Technical Details · 2026-03-10: 303-10
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-24310 Authenticated Information Disclosure in SAP NetWeaver Application Server for ABAP https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-24310

    Post summary

    The post announces CVE-2026-24310, describing it as an authenticated information disclosure vulnerability in SAP NetWeaver, but offers no additional technical depth, PoC, or mitigation details.

    0000031
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-24310 Due to missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker could execute specific ABAP function module and read the se… https://www.cve.org/CVERecord?id=CVE-2026-24310 ----- Traducción: CVE-2026-24310 Deb… http://infoflow.cloud`

    Post summary

    The post discloses CVE‑2026‑24310, a missing authorization check in SAP NetWeaver that allows an authenticated attacker to run an ABAP function module and read data, but provides no PoC, exploit, patch, or claim of active use.

    0000044
    57 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-24310 Due to missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker could execute specific ABAP function module and read the se… https://www.cve.org/CVERecord?id=CVE-2026-24310

    Post summary

    The text reports CVE‑2026‑24310, noting a missing authorization check in SAP NetWeaver that lets an authenticated attacker run a function module and read data; no PoC, exploit, patch, or active exploitation is mentioned.

    00000184
    56.7K followersView on X
CPE platform detail13 entries

13 of 13 entries

PartVendorProductVersionTarget SWTarget HW
Appsapnetweaver_application_server_abap702--
Appsapnetweaver_application_server_abap731--
Appsapnetweaver_application_server_abap740--
Appsapnetweaver_application_server_abap750--
Appsapnetweaver_application_server_abap751--
Appsapnetweaver_application_server_abap752--
Appsapnetweaver_application_server_abap753--
Appsapnetweaver_application_server_abap754--
Appsapnetweaver_application_server_abap755--
Appsapnetweaver_application_server_abap756--
Appsapnetweaver_application_server_abap757--
Appsapnetweaver_application_server_abap758--
Appsapnetweaver_application_server_abap816--

Explore more