medium2026-08-11SAP NetWeaverCVE-2026-58241
Missing Authorization Check in SAP NetWeaver CTS Transport Management System Controller
SAP NetWeaver Change and Transport System (TMS Controller)
Our Take
The CTS TMS Controller manages transport routes and import queues. Unauthorised access here could allow an attacker to manipulate transport flows — a change management and audit concern. Next planned window.
Vulnerability Detail
A missing authorisation check in the Transport Management System (TMS) Controller component of the SAP Change and Transport System allows an authenticated attacker to access transport management functions beyond their intended permissions.
Patch Action
Apply SAP Note 3752864. Verify affected versions in the official SAP Note.
Patch Info