
Cloud Vulnerability DB
Eine von der Community geführte Datenbank für Schwachstellen
CVE-2026-66767 is a session hijacking vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform that allows an unauthenticated attacker to send a specially crafted packet triggering reprocessing of a previously buffered user request, potentially hijacking another user's session under narrow timing conditions. The vulnerability was published on September 8, 2026, and affects multiple kernel versions including KRNL64NUC 7.22, KRNL64UC 7.22, KERNEL 7.22, 7.53, 7.54, 7.77, 7.93, 8.04, 9.16, 9.18, 9.19, and 9.20. It carries a CVSS v3.1 base score of 7.7 (High) (GitHub Advisory).
The root cause is classified as CWE-191 (Integer Underflow / Wrap or Wraparound), where a subtraction operation produces a value below the minimum allowable integer, leading to incorrect processing of buffered request data. An unauthenticated remote attacker exploits a race condition in the request buffering mechanism by sending a specially crafted network packet that causes the server to reprocess a previously buffered request belonging to another authenticated user, effectively inheriting that user's session context. Exploitation requires high attack complexity due to the narrow timing window required to trigger the race condition, and no user interaction or prior privileges are needed (GitHub Advisory).
Successful exploitation results in high impact on confidentiality and integrity, with low impact on availability. An attacker who wins the race condition gains access to another user's authenticated session, potentially allowing them to read sensitive business data, perform unauthorized transactions, or modify data within the hijacked user's permissions on the SAP NetWeaver system. Given SAP NetWeaver's role as a core enterprise ERP platform, a compromised session could expose critical business processes, financial data, and HR records (GitHub Advisory, Onapsis Blog).
There is no known public proof-of-concept exploit and no evidence of active in-the-wild exploitation at this time. The NVD SSVC assessment classifies the vulnerability as non-automatable, reflecting the high attack complexity imposed by the narrow timing window required for successful exploitation. The EPSS score is approximately 0.26% (18th percentile), indicating a low near-term probability of exploitation. No threat actor attribution has been reported, and the vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities catalog (GitHub Advisory).
SAP has released a patch for this vulnerability, referenced in SAP Security Note 3757002, available via the SAP Support Portal. Organizations should apply the relevant kernel patch for their affected version as the primary remediation step. As interim workarounds, SAP recommends monitoring for suspicious session activity and unexpected request reprocessing patterns, and implementing network-level controls to restrict access to the NetWeaver Application Server to trusted networks only. Refer to the SAP Security Patch Day September 2026 guidance for full patching instructions (SAP Note, SAP Patch Day).
The vulnerability was covered as part of SAP's September 2026 Security Patch Day, which addressed 19 new vulnerabilities across SAP products. Security firms including Onapsis, SecurityBridge, and RedRays published patch day summaries highlighting this flaw alongside other critical issues patched in the same release cycle. Coverage from outlets such as GBHackers, CyberSecurityNews, and Cryptika noted the authentication bypass nature of the vulnerability and its potential impact on enterprise ERP environments (Onapsis Blog, SecurityBridge, GBHackers).
Quelle: Dieser Bericht wurde mithilfe von KI erstellt
Kostenlose Schwachstellenbewertung
Bewerten Sie Ihre Cloud-Sicherheitspraktiken in 9 Sicherheitsbereichen, um Ihr Risikoniveau zu bewerten und Lücken in Ihren Abwehrmaßnahmen zu identifizieren.
Eine personalisierte Demo anfordern
"Die beste Benutzererfahrung, die ich je gesehen habe, bietet vollständige Transparenz für Cloud-Workloads."
"„Wiz bietet eine zentrale Oberfläche, um zu sehen, was in unseren Cloud-Umgebungen vor sich geht.“ "
"„Wir wissen, dass, wenn Wiz etwas als kritisch identifiziert, es auch wirklich kritisch ist.“"