Critical severity9.6NVD Advisory· Published Jan 13, 2026· Updated Jun 17, 2026
CVE-2026-0500
CVE-2026-0500
Description
Due to the usage of vulnerable third party component in SAP Wily Introscope Enterprise Manager (WorkStation), an unauthenticated attacker could create a malicious JNLP (Java Network Launch Protocol) file accessible by a public facing URL. When a victim clicks on the URL the accessed Wily Introscope Server could execute OS commands on the victim's machine. This could completely compromising confidentiality, integrity and availability of the system.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:sap:introscope_enterprise_manager:10.8:*:*:*:*:*:*:*
- Range: WILY_INTRO_ENTERPRISE 10.8
Patches
Vulnerability mechanics
References
2- url.sap/sapsecuritypatchdaynvdPatchVendor Advisory
- me.sap.com/notes/3668679nvdPermissions Required
News mentions
0No linked articles in our index yet.