Medium severity5.0NVD Advisory· Published Feb 10, 2026· Updated Jun 17, 2026
CVE-2026-0486
CVE-2026-0486
Description
In ABAP based SAP systems a remote enabled function module does not perform necessary authorization checks for an authenticated user resulting in disclosure of system information.This has low impact on confidentiality. Integrity and availability are not impacted.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6- SAP_SE/ABAP based SAP systemsv5Range: ST-PI 2005_1_700
cpe:2.3:a:sap:solution_tools_plug-in:740:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:sap:solution_tools_plug-in:740:*:*:*:*:*:*:*
- cpe:2.3:a:sap:solution_tools_plug-in:758:*:*:*:*:*:*:*
- cpe:2.3:a:sap:solution_tools_plug-in:2005_1_700:*:*:*:*:*:*:*
- cpe:2.3:a:sap:solution_tools_plug-in:2008_1_710:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
2- url.sap/sapsecuritypatchdaynvdVendor Advisory
- me.sap.com/notes/3691645nvdPermissions Required
News mentions
0No linked articles in our index yet.