PT-2026-86951 · Sap Se · Sap Netweaver Application Server For Abap/Abap Platform

CVE-2026-66767

·

Published

2026-09-08

·

Updated

2026-09-08

CVSS v3.1

7.7

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
SAP NetWeaver Application Server for ABAP and ABAP Platform allows an unauthenticated user to send a specially crafted packet that triggers reprocessing of a previously buffered user request, potentially hijacking another user's session under narrow timing conditions. Successful exploitation could result in high impact on confidentiality and integrity, with low impact on availability of the application.

Fix

Integer Underflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-66767

Affected Products

Sap Netweaver Application Server For Abap/Abap Platform