SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated, low-privileged user to perform background Remote Function Calls without the required S_RFC authorization in certain cases. This can result in a high impact on integrity and availability, and no impact on the confidentiality of the application.

Published: 2026-02-10

CVSS: 9.6

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H

Download CVE-2026-0509 POC (Proof-of-Concept) here:

Tip: Download official Tor Browser at https://www.torproject.org/download/ to access .onion links.

Check our portfolio:

https://dnacompany.com/poc-682-cve-2026-27613/

https://dnacompany.com/poc-13-cve-2025-66480/

https://dnacompany.com/poc-374-cve-2026-2684/

https://dnacompany.com/poc-1-cve-2026-25069/

https://dnacompany.com/poc-52-cve-2020-37066/