CVE-2026-66767

7.7

SAP · NetWeaver Application Server for ABAP and ABAP Platform

SAP NetWeaver allows unauthenticated users to hijack sessions via a crafted packet that triggers the reprocessing of buffered requests under specific timing conditions.

Executive summary

A critical session hijacking vulnerability in SAP NetWeaver Application Server for ABAP permits unauthenticated attackers to compromise user sessions via crafted packets.

Vulnerability

This vulnerability, categorized as an integer underflow (CWE-191), allows unauthenticated attackers to manipulate buffered user requests. By sending a specially crafted packet, an attacker can force the application to reprocess data, potentially leading to unauthorized session hijacking.

Business impact

The vulnerability carries a CVSS score of 7.7, reflecting a high risk to both data confidentiality and system integrity. Successful exploitation could allow an attacker to impersonate legitimate users, potentially gaining access to sensitive business data, financial records, or administrative functions within the SAP environment.

Remediation

Immediate Action: Review the official SAP Security Note 3757002 and apply all recommended patches or kernel updates provided by the vendor.

Proactive Monitoring: Monitor network traffic for unusual packet sequences directed at SAP application servers and review system logs for anomalies related to session management or unexpected user request processing.

Compensating Controls: Deploy a Web Application Firewall (WAF) with updated rulesets to detect and block malformed packets that might attempt to trigger the vulnerable request buffering mechanism.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the high CVSS score and the potential for full session compromise, organizations running the affected SAP versions must prioritize this update. Administrators should consult the referenced SAP security note immediately to verify if their specific kernel version requires patching or configuration changes to mitigate the session hijacking risk.

More SAP CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources