{"api_version":"1","generated_at":"2026-08-02T11:06:26+00:00","cve":"CVE-2026-58246","urls":{"html":"https://cve.report/CVE-2026-58246","api":"https://cve.report/api/cve/CVE-2026-58246.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-58246","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-58246"},"summary":{"title":"Information Disclosure vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform","description":"SAP NetWeaver Application Server for ABAP and ABAP Platform writes sensitive session identifier information into a diagnostic trace when the trace is activated by a privileged user. An attacker with access to the resulting trace data could obtain identifiers that allow impersonation of legitimate users during their validity period. This leads to high impact on confidentiality. Integrity and availability are not impacted.","state":"PUBLISHED","assigner":"sap","published_at":"2026-07-28 10:16:49","updated_at":"2026-07-28 20:17:27"},"problem_types":["CWE-497","CWE-497 CWE-497 Exposure of sensitive system information to an unauthorized control sphere"],"metrics":[{"version":"3.1","source":"cna@sap.com","type":"Secondary","score":"4.3","severity":"MEDIUM","vector":"CVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"4.3","severity":"MEDIUM","vector":"CVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N","data":{"attackComplexity":"LOW","attackVector":"ADJACENT_NETWORK","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","integrityImpact":"NONE","privilegesRequired":"HIGH","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N","version":"3.1"}}],"references":[{"url":"https://url.sap/sapsecuritypatchday","name":"https://url.sap/sapsecuritypatchday","refsource":"cna@sap.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://me.sap.com/notes/3413033","name":"https://me.sap.com/notes/3413033","refsource":"cna@sap.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-58246","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-58246","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"SAP_SE","product":"SAP NetWeaver Application Server for ABAP","version":"affected SAP_BASIS 740","platforms":["ABAP"]},{"source":"CNA","vendor":"SAP_SE","product":"SAP NetWeaver Application Server for ABAP","version":"affected SAP_BASIS 750","platforms":["ABAP"]},{"source":"CNA","vendor":"SAP_SE","product":"SAP NetWeaver Application Server for ABAP","version":"affected SAP_BASIS 751","platforms":["ABAP"]},{"source":"CNA","vendor":"SAP_SE","product":"SAP NetWeaver Application Server for ABAP","version":"affected SAP_BASIS 752","platforms":["ABAP"]},{"source":"CNA","vendor":"SAP_SE","product":"SAP NetWeaver Application Server for ABAP","version":"affected SAP_BASIS 753","platforms":["ABAP"]},{"source":"CNA","vendor":"SAP_SE","product":"SAP NetWeaver Application Server for ABAP","version":"affected SAP_BASIS 754","platforms":["ABAP"]},{"source":"CNA","vendor":"SAP_SE","product":"SAP NetWeaver Application Server for ABAP","version":"affected SAP_BASIS 755","platforms":["ABAP"]},{"source":"CNA","vendor":"SAP_SE","product":"SAP NetWeaver Application Server for ABAP","version":"affected SAP_BASIS 756","platforms":["ABAP"]},{"source":"CNA","vendor":"SAP_SE","product":"SAP NetWeaver Application Server for ABAP","version":"affected SAP_BASIS 757","platforms":["ABAP"]},{"source":"CNA","vendor":"SAP_SE","product":"SAP NetWeaver Application Server for ABAP","version":"affected SAP_BASIS 758","platforms":["ABAP"]},{"source":"CNA","vendor":"SAP_SE","product":"SAP NetWeaver Application Server for ABAP","version":"affected SAP_BASIS 795","platforms":["ABAP"]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"58246","cve":"CVE-2026-58246","epss":"0.001500000","percentile":"0.047060000","score_date":"2026-07-29","updated_at":"2026-07-30 00:09:13"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-58246","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2026-07-28T19:16:44.559113Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-07-28T19:16:55.291Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"defaultStatus":"unaffected","platforms":["ABAP"],"product":"SAP NetWeaver Application Server for ABAP","vendor":"SAP_SE","versions":[{"status":"affected","version":"SAP_BASIS 740"},{"status":"affected","version":"SAP_BASIS 750"},{"status":"affected","version":"SAP_BASIS 751"},{"status":"affected","version":"SAP_BASIS 752"},{"status":"affected","version":"SAP_BASIS 753"},{"status":"affected","version":"SAP_BASIS 754"},{"status":"affected","version":"SAP_BASIS 755"},{"status":"affected","version":"SAP_BASIS 756"},{"status":"affected","version":"SAP_BASIS 757"},{"status":"affected","version":"SAP_BASIS 758"},{"status":"affected","version":"SAP_BASIS 795"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:a:sap_se:sap_netweaver_application_server_for_abap:sap_basis_740:*:abap:*:*:*:*:*","vulnerable":true},{"criteria":"cpe:2.3:a:sap_se:sap_netweaver_application_server_for_abap:sap_basis_750:*:abap:*:*:*:*:*","vulnerable":true},{"criteria":"cpe:2.3:a:sap_se:sap_netweaver_application_server_for_abap:sap_basis_751:*:abap:*:*:*:*:*","vulnerable":true},{"criteria":"cpe:2.3:a:sap_se:sap_netweaver_application_server_for_abap:sap_basis_752:*:abap:*:*:*:*:*","vulnerable":true},{"criteria":"cpe:2.3:a:sap_se:sap_netweaver_application_server_for_abap:sap_basis_753:*:abap:*:*:*:*:*","vulnerable":true},{"criteria":"cpe:2.3:a:sap_se:sap_netweaver_application_server_for_abap:sap_basis_754:*:abap:*:*:*:*:*","vulnerable":true},{"criteria":"cpe:2.3:a:sap_se:sap_netweaver_application_server_for_abap:sap_basis_755:*:abap:*:*:*:*:*","vulnerable":true},{"criteria":"cpe:2.3:a:sap_se:sap_netweaver_application_server_for_abap:sap_basis_756:*:abap:*:*:*:*:*","vulnerable":true},{"criteria":"cpe:2.3:a:sap_se:sap_netweaver_application_server_for_abap:sap_basis_757:*:abap:*:*:*:*:*","vulnerable":true},{"criteria":"cpe:2.3:a:sap_se:sap_netweaver_application_server_for_abap:sap_basis_758:*:abap:*:*:*:*:*","vulnerable":true},{"criteria":"cpe:2.3:a:sap_se:sap_netweaver_application_server_for_abap:sap_basis_795:*:abap:*:*:*:*:*","vulnerable":true}],"negate":false,"operator":"OR"}],"operator":"OR"}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<div><p>SAP NetWeaver Application Server for ABAP and ABAP Platform writes sensitive session identifier information into a diagnostic trace when the trace is activated by a privileged user. An attacker with access to the resulting trace data could obtain identifiers that allow impersonation of legitimate users during their validity period.&nbsp;This leads to high impact on confidentiality. Integrity and availability are not impacted.</p></div><br>"}],"value":"SAP NetWeaver Application Server for ABAP and ABAP Platform writes sensitive session identifier information into a diagnostic trace when the trace is activated by a privileged user. An attacker with access to the resulting trace data could obtain identifiers that allow impersonation of legitimate users during their validity period. This leads to high impact on confidentiality. Integrity and availability are not impacted."}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"ADJACENT_NETWORK","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","integrityImpact":"NONE","privilegesRequired":"HIGH","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-497","description":"CWE-497 Exposure of sensitive system information to an unauthorized control sphere","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-07-28T09:51:55.180Z","orgId":"e4686d1a-f260-4930-ac4c-2f5c992778dd","shortName":"sap"},"references":[{"url":"https://me.sap.com/notes/3413033"},{"url":"https://url.sap/sapsecuritypatchday"}],"source":{"discovery":"UNKNOWN"},"title":"Information Disclosure vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform","x_generator":{"engine":"Vulnogram 1.0.4"}}},"cveMetadata":{"assignerOrgId":"e4686d1a-f260-4930-ac4c-2f5c992778dd","assignerShortName":"sap","cveId":"CVE-2026-58246","datePublished":"2026-07-28T09:51:55.180Z","dateReserved":"2026-06-29T19:35:04.186Z","dateUpdated":"2026-07-28T19:16:55.291Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-07-28 10:16:49","lastModifiedDate":"2026-07-28 20:17:27","problem_types":["CWE-497","CWE-497 CWE-497 Exposure of sensitive system information to an unauthorized control sphere"],"metrics":{"cvssMetricV31":[{"source":"cna@sap.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":0.7,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-28T19:16:44.559113Z","id":"CVE-2026-58246","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"58246","Ordinal":"1","Title":"Information Disclosure vulnerability in SAP NetWeaver Applicatio","CVE":"CVE-2026-58246","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"58246","Ordinal":"1","NoteData":"SAP NetWeaver Application Server for ABAP and ABAP Platform writes sensitive session identifier information into a diagnostic trace when the trace is activated by a privileged user. An attacker with access to the resulting trace data could obtain identifiers that allow impersonation of legitimate users during their validity period. This leads to high impact on confidentiality. Integrity and availability are not impacted.","Type":"Description","Title":"Information Disclosure vulnerability in SAP NetWeaver Applicatio"}]}}}