CVE-2026-76967
SAP NetWeaver Business Client does not perform sufficient validation when processing certain locally stored data during application startup. An attacker with low privileges on the local system could replace this data with specially crafted content. When the application is next launched, the crafted content is processed and could lead to arbitrary code execution in the context of the user. This results in a high impact on confidentiality, integrity and availability of the application.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.8
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 0.22%
- CWE
- CWE-502
- Published
- 2026-09-08
- Last modified
- 2026-09-09
Affected products
- SAP_SE SAP NetWeaver Business Client
- SAP_SE SAP NetWeaver Business Client
Weakness type
Related vulnerabilities
- CVE-2026-87930 — MaxSite CMS through 109.6 PHP Object Injection via ci_session
- CVE-2026-87874 — Community.general: community.general: memcached cache plugin deserializes untrusted pickle data from memcached, enabling cache-poisoning remote code execution on the ansible controller
- CVE-2024-58381 — PocketMine-MP before 5.11.1 Denial of Service via LoginPacket
- CVE-2026-11363 — Ninja Forms <= 3.14.6 - Authenticated (Administrator+) PHP Object Injection via Form Import
- CVE-2026-87083 — tile-ai tilelang Kernel Cache kernel_cache.py KernelCache._load_kernel_from_disk deserialization
- CVE-2026-81385 — Microsoft Office Publisher Remote Code Execution Vulnerability
- CVE-2026-77484 — Microsoft SQL Server Remote Code Execution Vulnerability
- CVE-2026-65772 — Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability