CVE-2026-40135General(sap / netweaver_application_server_abap)

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

An OS Command Injection vulnerability exists in the SAP NetWeaver Application Server for ABAP and ABAP Platform that allows an authenticated attacker with administrative access to execute specially crafted shell commands on the server, bypassing the logging mechanism. This allows the execution of unintended OS commands without detection, potentially impacting the integrity and availability of the application, with no impact on confidentiality.

0.0/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-77

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • netweaver_application_server_abap

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • General: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-05-12); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
netweaver_application_server_abap

15 versions affected across 1 product

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-05-12: 1Mentions · 2026-05-14: 1Technical Details · 2026-05-12: 1Technical Details · 2026-05-14: 105-1205-14
Signal classification2 categories
General
150.0%
Disclosure
150.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-05-121
General1
2026-05-141
Disclosure1
Full discourse2 posts
  • AbOUk | East Africa Tech@abokfelix
    Disclosure

    4/6: Beyond the Criticals It's not just the 9.6 flaws. We're seeing: 🔥 CVE-2026-34259 (CVSS 8.2): OS Command Injection in SAP Forecasting & Replenishment. 🔥 CVE-2026-40135 (CVSS 6.5): Similar injection flaw in NetWeaver AS ABAP. Attackers are increasingly targeting these "sidecar" applications to gain a foothold in the network.

    Post summary

    The post discloses two new SAP component vulnerabilities (OS Command Injection) with CVSS scores, warning that attackers are increasingly targeting these sidecar applications for network footholds.

    1000047
    7.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-40135 OS Command Injection in SAP NetWeaver Application Server for ABAP https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-40135

    Post summary

    The entry identifies a CVE (CVE-2026-40135) involving OS command injection in SAP NetWeaver but offers only basic vulnerability labeling without details on exploitation, mitigation, or PoC.

    0000061
    4.0K followersView on X
CPE platform detail15 entries

15 of 15 entries

PartVendorProductVersionTarget SWTarget HW
Appsapnetweaver_application_server_abap700--
Appsapnetweaver_application_server_abap701--
Appsapnetweaver_application_server_abap702--
Appsapnetweaver_application_server_abap731--
Appsapnetweaver_application_server_abap740--
Appsapnetweaver_application_server_abap750--
Appsapnetweaver_application_server_abap751--
Appsapnetweaver_application_server_abap752--
Appsapnetweaver_application_server_abap753--
Appsapnetweaver_application_server_abap754--
Appsapnetweaver_application_server_abap755--
Appsapnetweaver_application_server_abap756--
Appsapnetweaver_application_server_abap757--
Appsapnetweaver_application_server_abap758--
Appsapnetweaver_application_server_abap816--

Explore more