What is CVE-2026-34265?
SAP NetWeaver Application Server ABAP contains a logical error in DIAG protocol parsing that allows an unauthenticated attacker to cause memory corruption. This vulnerability may lead to the disclosure of sensitive system information or system crashes, posing a high risk to confidentiality. Applying the security patch released by SAP is recommended.
Azərbaycanca: SAP NetWeaver Application Server ABAP-da DIAG protokolunun işlənməsindəki məntiqi səhv autentifikasiya olunmamış hücumçuya yaddaş korrupsiyasına səbəb olmağa imkan verir. Bu zəiflik həssas sistem məlumatlarının ifşasına və ya sistemin çökməsinə gətirib çıxara bilər. SAP tərəfindən buraxılmış təhlükəsizlik yamasının tətbiq edilməsi tövsiyə olunur.
Related CVEs
link basis: shared vendor: SAP
FAQ2
Which protocol is affected by CVE-2026-34265 in SAP NetWeaver AS ABAP?
This vulnerability is based on a logical error in DIAG protocol parsing.
What are the potential consequences of CVE-2026-34265?
It can cause memory corruption, potentially leading to the disclosure of sensitive system information or system crashes.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.