CVE-2026-66767
SAP NetWeaver Application Server for ABAP and ABAP Platform allows an unauthenticated user to send a specially crafted packet that triggers reprocessing of a previously buffered user request, potentially hijacking another user's session under narrow timing conditions. Successful exploitation could result in high impact on confidentiality and integrity, with low impact on availability of the application.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.7
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
- EPSS probability
- 0.26%
- CWE
- CWE-191
- Published
- 2026-09-08
- Last modified
- 2026-09-09
Affected products
- SAP_SE SAP NetWeaver Application Server for ABAP and ABAP Platform
- SAP_SE SAP NetWeaver Application Server for ABAP and ABAP Platform
- SAP_SE SAP NetWeaver Application Server for ABAP and ABAP Platform
- SAP_SE SAP NetWeaver Application Server for ABAP and ABAP Platform
- SAP_SE SAP NetWeaver Application Server for ABAP and ABAP Platform
- SAP_SE SAP NetWeaver Application Server for ABAP and ABAP Platform
- SAP_SE SAP NetWeaver Application Server for ABAP and ABAP Platform
- SAP_SE SAP NetWeaver Application Server for ABAP and ABAP Platform
Weakness type
Related vulnerabilities
- CVE-2026-81977 — Acrobat Reader | Integer Underflow (Wrap or Wraparound) (CWE-191)
- CVE-2026-66307 — Skype for Business and Lync Denial of Service Vulnerability
- CVE-2026-78453 — Microsoft Windows SCSI Class System File Information Disclosure Vulnerability
- CVE-2026-77488 — Microsoft SQL Server Information Disclosure Vulnerability
- CVE-2026-71352 — Windows Remote Access Connection Manager Remote Code Execution Vulnerability
- CVE-2026-69824 — Microsoft Standard XPS Remote Code Execution Vulnerability
- CVE-2026-69687 — Windows USB Audio Class driver (usbaudio.sys) Elevation of Privilege Vulnerability
- CVE-2026-69421 — Windows Kernel-Mode Driver Elevation of Privilege Vulnerability