CVE-2026-24320

Published Feb 10, 2026

Last updated 15 days ago

Overview

Description
Due to improper memory management in SAP NetWeaver and ABAP Platform (Application Server ABAP), an authenticated attacker could exploit logical errors in memory management by supplying specially crafted input containing unique characters, which are improperly converted. This may result in memory corruption and the potential leakage of memory content. Successful exploitation of this vulnerability would have a low impact on the confidentiality of the application, with no effect on its integrity or availability.
Source
cna@sap.com
NVD status
Analyzed
Products
netweaver_as_abap_kernel, netweaver_as_abap_krnl64nuc, netweaver_as_abap_krnl64uc

Risk scores

CVSS 3.1

Type
Primary
Base score
3.1
Impact score
1.4
Exploitability score
1.6
Vector string
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Severity
LOW

Weaknesses

cna@sap.com
CWE-113
nvd@nist.gov
CWE-787

Social media

Hype score
Not currently trending

Configurations

References

Sources include official advisories and independent security research.