CVE-2026-0500 is a critical vulnerability in SAP Wily Introscope Enterprise Manager (WorkStation) stemming from a vulnerable third-party component. An unauthenticated attacker can craft a malicious JNLP file, which, when accessed by a victim, allows for remote OS command execution on their machine, leading to complete compromise of confidentiality, integrity, and availability. This vulnerability has a CVSS score of 8.8 (High) due to its network attack vector, low attack complexity, and high impact on all security aspects, requiring only user interaction. While there is no evidence of active exploitation or publicly available exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community attention with 13 mentions and media coverage, indicating a high level of awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
10.8CPE matchmatch criteria | cpe:2.3:a:sap:introscope_enterprise_manager:10.8:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.