medium2026-08-11SAP NetWeaverCVE-2026-58236

OS Command Injection in SAP NetWeaver Component BC-CST-DP

SAP NetWeaver (BC-CST-DP)

Our Take

OS command injection at medium severity (authenticated required, constrained impact). Next planned window.

Vulnerability Detail

An OS command injection vulnerability in the BC-CST-DP component of SAP NetWeaver allows an authenticated attacker to inject operating system commands through unsanitised input, with potential for arbitrary command execution on the application server.

Patch Action

Apply SAP Note 3745182. Verify the specific component and affected versions in the official SAP Note.

Patch Info

CVSS Score

5.5

SAP Note

3745182

CVE

CVE-2026-58236

Published

2026-08-11

← All patches