CVE-2026-76967

7.8

SAP · NetWeaver Business Client

SAP NetWeaver Business Client is vulnerable to arbitrary code execution due to insufficient validation of locally stored data during application startup.

Executive summary

A high-severity deserialization vulnerability in SAP NetWeaver Business Client allows local attackers with low privileges to execute arbitrary code.

Vulnerability

This flaw involves the deserialization of untrusted data (CWE-502) stored locally by the application. An attacker with low-level local access can overwrite this data, triggering arbitrary code execution when the application is launched by a user.

Business impact

Successful exploitation allows an attacker to gain the same execution context as the victim user, leading to a total compromise of confidentiality, integrity, and availability for the affected client. Given the CVSS score of 7.8, this vulnerability poses a significant risk to workstations and end-user environments where SAP NetWeaver is deployed, potentially facilitating lateral movement or data exfiltration.

Remediation

Immediate Action: Review the official SAP Security Note 3784138 and apply the recommended security updates or configuration changes provided by the vendor.

Proactive Monitoring: Monitor local system logs for unauthorized access to application configuration directories or unexpected modifications to data files associated with the Business Client.

Compensating Controls: Implement strict file system permissions to ensure only authorized users can modify application data directories, effectively preventing low-privileged users from tampering with the vulnerable files.

Exploitation status

Public Exploit Available: No

Analyst recommendation

This vulnerability represents a significant security risk for SAP environments due to the potential for arbitrary code execution. Organizations should prioritize assessing their workstation deployments for the affected versions of NetWeaver Business Client and apply the vendor-supplied patches as soon as they become available to prevent local privilege escalation.

More SAP CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources