SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could significantly affect the confidentiality, integrity, and availability of the targeted system.
Use CWE-434, Sap vendor hub and Netweaver product page to widen CVE-2025-31324 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2025-42999, CVE-2023-36922 and CVE-2023-33984 for nearby disclosures in the same product family. Additional editorial context is available in The Weekly Cybersecurity Brief: February 13th, 2026.