CVE-2026-76967
7.8SAP · NetWeaver Business Client
SAP NetWeaver Business Client is vulnerable to arbitrary code execution due to insufficient validation of locally stored data during application startup.
Executive summary
A high-severity deserialization vulnerability in SAP NetWeaver Business Client allows local attackers with low privileges to execute arbitrary code.
Vulnerability
This flaw involves the deserialization of untrusted data (CWE-502) stored locally by the application. An attacker with low-level local access can overwrite this data, triggering arbitrary code execution when the application is launched by a user.
Business impact
Successful exploitation allows an attacker to gain the same execution context as the victim user, leading to a total compromise of confidentiality, integrity, and availability for the affected client. Given the CVSS score of 7.8, this vulnerability poses a significant risk to workstations and end-user environments where SAP NetWeaver is deployed, potentially facilitating lateral movement or data exfiltration.
Remediation
Immediate Action: Review the official SAP Security Note 3784138 and apply the recommended security updates or configuration changes provided by the vendor.
Proactive Monitoring: Monitor local system logs for unauthorized access to application configuration directories or unexpected modifications to data files associated with the Business Client.
Compensating Controls: Implement strict file system permissions to ensure only authorized users can modify application data directories, effectively preventing low-privileged users from tampering with the vulnerable files.
Exploitation status
Public Exploit Available: No
Analyst recommendation
This vulnerability represents a significant security risk for SAP environments due to the potential for arbitrary code execution. Organizations should prioritize assessing their workstation deployments for the affected versions of NetWeaver Business Client and apply the vendor-supplied patches as soon as they become available to prevent local privilege escalation.
More SAP CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section