SAP fixes four critical auth, code-injection and memory flaws

SAP’s August 2026 patches fix four critical flaws in Commerce Cloud, Manufacturing Integration and Intelligence and NetWeaver ABAP, including a CVSS 10.0 authentication bypass.

On its August 2026 Security Patch Day, SAP released 28 new security notes, two note updates and a GitHub advisory. Four of the new notes address critical vulnerabilities across Commerce Cloud, Manufacturing Integration and Intelligence, and Application Server ABAP for NetWeaver.

The most severe is CVE-2026-58231, an improper authorization issue in the Data Hub Adapter for SAP Commerce Cloud. It has a CVSS score of 10.0 and can allow remote attackers to bypass authentication, potentially leading to code execution and unauthorized access to internal components.

SAP also fixed two code-injection flaws in Manufacturing Integration and Intelligence: CVE-2026-44772 (CVSS 9.9) and CVE-2026-44758 (CVSS 9.1). Vulnerable servlets accept specially crafted input that can result in execution of arbitrary commands on the underlying host and broader infrastructure compromise. Security firm Onapsis noted the two bugs are similar but that one requires higher privileges to exploit.

The fourth critical issue, CVE-2026-34265 (CVSS 9.8), is a memory corruption defect in Application Server ABAP for NetWeaver and ABAP Platform. The error is rooted in logical faults when parsing the DIAG protocol. It can be triggered without authentication and may disclose sensitive information or crash affected systems.

SAP updated a critical note first posted on the July 2026 Patch Day to add information about a previously reported NetWeaver memory corruption issue.

Beyond the four critical flaws, SAP published eight high-severity notes covering ABAP Developer Tools, Commerce Cloud, the Change and Transport System Attach Tool, BusinessObjects, Manufacturing Integration and Intelligence, and the Business AI Platform (Approuter). The high-severity notes address privilege escalation, buffer overflow, remote code execution, credential disclosure, directory traversal and missing authorization checks. One note resolves 11 defects in Approuter. The remaining notes address medium- and low-severity vulnerabilities.

SAP did not report any of the August vulnerabilities as being exploited in the wild. Administrators running affected SAP products should review the vendor’s security notes, apply available patches and follow the recommended mitigations in the advisory materials. The notes include technical details and temporary workarounds for environments that cannot be updated immediately.

SAP publishes security updates on a monthly schedule.

Articles by this author