PT-2026-57948 · Sap · Sap Change/Transport System Attach Tool

CVE-2026-58233

·

Published

2026-07-14

·

Updated

2026-07-16

CVSS v2.0

8.7

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:P
Name of the Vulnerable Software and Affected Versions SAP Change and Transport System Attach Tool (ctsattach) (affected versions not specified)
Description An authenticated attacker can provide a specially crafted archive file that triggers insecure deserialization when processed by the application library. Insecure deserialization occurs when untrusted data is used to abuse the logic of an application to execute arbitrary code. This can lead to remote code execution (RCE), allowing the attacker to extract sensitive information and gain control over the system and its processes.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. Restrict archive processing to minimize the risk of exploitation.

RCE

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-09893
CVE-2026-58233

Affected Products

Sap Change/Transport System Attach Tool