high2026-08-11SAP ABAP DevelopmentCVE-2026-58243

Privilege Escalation via Insufficient Authorization in SAP ABAP Developer Tools

SAP ABAP Developer Tools (Eclipse ADT)

Our Take

ABAP Developer Tools is the Eclipse-based IDE used by ABAP developers — it should already be restricted to a small developer population. If your landscape gives broader access to ADT, tighten that first. Patch within two weeks.

Vulnerability Detail

Insufficient authorization checks in SAP ABAP Developer Tools (Eclipse ADT) allow a low-privileged attacker to perform unauthorized database operations that should require elevated permissions. Successful exploitation could enable an attacker to read, modify, or delete database records beyond their intended access scope.

Workaround

Review and tighten authorization assignments for ADT users. Restrict ADT access to developer roles only — it should not be accessible to general end users.

Patch Action

Apply SAP Note 3772411. Verify affected versions in the official SAP Note.

Patch Info

CVSS Score

8.8

SAP Note

3772411

CVE

CVE-2026-58243

Published

2026-08-11

← All patches