CVE-2026-0498
Severity CVSS v4.0:
Pending analysis
Type:
CWE-94
Code Injection
Publication date:
13/01/2026
Last modified:
22/01/2026
Description
SAP S/4HANA (Private Cloud and On-Premise) allows an attacker with admin privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injection of arbitrary ABAP code/OS commands into the system, bypassing essential authorization checks. This vulnerability effectively functions as a backdoor, creating the risk of full system compromise, undermining the confidentiality, integrity and availability of the system.
Impact
Base Score 3.x
9.10
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:sap:s\/4_hana:102:*:*:*:*:*:*:* | ||
| cpe:2.3:a:sap:s\/4_hana:103:*:*:*:*:*:*:* | ||
| cpe:2.3:a:sap:s\/4_hana:104:*:*:*:*:*:*:* | ||
| cpe:2.3:a:sap:s\/4_hana:105:*:*:*:*:*:*:* | ||
| cpe:2.3:a:sap:s\/4_hana:106:*:*:*:*:*:*:* | ||
| cpe:2.3:a:sap:s\/4_hana:107:*:*:*:*:*:*:* | ||
| cpe:2.3:a:sap:s\/4_hana:108:*:*:*:*:*:*:* | ||
| cpe:2.3:a:sap:s\/4_hana:109:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



