SAP S/4HANA ABAP Code Injection Vulnerability via RFC

Vulnerability

A vulnerability in SAP S/4HANA (Private Cloud and On-Premise) allows an attacker with admin privileges to inject arbitrary ABAP code or operating system commands into the system, bypassing critical authorization checks. This vulnerability, present in a function module exposed through Remote Function Call (RFC), effectively acts as a backdoor, posing a risk of complete system compromise and undermining the system's confidentiality, integrity, and availability.

Impact

Exploitation of this vulnerability could lead to a full system compromise, allowing unauthorized access and control over the system, with potential exploitation of the underlying operating system.

Remediation

Users are advised to consult the SAP Security Notes for guidance on applying patches and addressing this vulnerability. This vulnerability will be addressed in the next SAP Security Patch Day, scheduled for November 10, 2026.

Added: Jan 13, 2026, 2:30 AM
Updated: Jan 13, 2026, 2:30 AM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
7.5
exploitability
4.4
remediation
0.0
relevance
2.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.