medium2026-08-11SAP NetWeaverCVE-2026-58241

Missing Authorization Check in SAP NetWeaver CTS Transport Management System Controller

SAP NetWeaver Change and Transport System (TMS Controller)

Our Take

The CTS TMS Controller manages transport routes and import queues. Unauthorised access here could allow an attacker to manipulate transport flows — a change management and audit concern. Next planned window.

Vulnerability Detail

A missing authorisation check in the Transport Management System (TMS) Controller component of the SAP Change and Transport System allows an authenticated attacker to access transport management functions beyond their intended permissions.

Patch Action

Apply SAP Note 3752864. Verify affected versions in the official SAP Note.

Patch Info

CVSS Score

4.2

SAP Note

3752864

CVE

CVE-2026-58241

Published

2026-08-11

← All patches