medium2026-08-11SAP NetWeaverCVE-2026-58246

Information Disclosure in SAP NetWeaver Internet Communication Framework

SAP NetWeaver Internet Communication Framework (ICF)

Our Take

ICF is the HTTP handler underpinning all NetWeaver web services and OData APIs. Information disclosure here can aid reconnaissance. Next planned BASIS window.

Vulnerability Detail

An information disclosure vulnerability in the SAP NetWeaver Internet Communication Framework (ICF) allows an authenticated attacker to access sensitive information beyond their intended permissions via the ICF request/response handling layer.

Patch Action

Apply SAP Note 3413033. Verify affected versions in the official SAP Note.

Patch Info

CVSS Score

4.3

SAP Note

3413033

CVE

CVE-2026-58246

Published

2026-08-11

← All patches