Description

An authenticated attacker in SAP CRM and SAP S/4HANA (Scripting Editor) could exploit a flaw in a generic function module call and execute unauthorized critical functionalities, which includes the ability to execute an arbitrary SQL statement. This leads to a full database compromise with high impact on confidentiality, integrity, and availability.

INFO

Published Date :

2026-02-10T03:01:08.999Z

Last Modified :

2026-02-10T15:44:17.342Z

Source :

sap
AFFECTED PRODUCTS

The following products are affected by CVE-2026-0488 vulnerability.

Vendors Products
Sap Se
  • Sap Crm And Sap S/4hana (scripting Editor)
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2026-0488.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact