medium2026-08-11SAP NetWeaverCVE-2026-58236
OS Command Injection in SAP NetWeaver Component BC-CST-DP
SAP NetWeaver (BC-CST-DP)
Our Take
OS command injection at medium severity (authenticated required, constrained impact). Next planned window.
Vulnerability Detail
An OS command injection vulnerability in the BC-CST-DP component of SAP NetWeaver allows an authenticated attacker to inject operating system commands through unsanitised input, with potential for arbitrary command execution on the application server.
Patch Action
Apply SAP Note 3745182. Verify the specific component and affected versions in the official SAP Note.
Patch Info