
Cloud Vulnerability DB
コミュニティ主導の脆弱性データベース
CVE-2026-66767 is a session hijacking vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform that allows an unauthenticated attacker to send a specially crafted packet triggering reprocessing of a previously buffered user request, potentially hijacking another user's session under narrow timing conditions. It was published on September 8, 2026, and affects multiple kernel versions including KRNL64NUC 7.22, KRNL64UC 7.22, KERNEL 7.22, 7.53, 7.54, 7.77, 7.93, 8.04, 9.16, 9.18, 9.19, and 9.20. The vulnerability carries a CVSS v3.1 base score of 7.7 (High) (GitHub Advisory).
The root cause is classified as CWE-191 (Integer Underflow / Wrap or Wraparound), where a subtraction operation produces a value below the minimum allowable integer, leading to incorrect buffer length calculations in the SAP kernel's request handling logic (GitHub Advisory). An unauthenticated attacker over the network can exploit this by sending a specially crafted network packet that causes the server to reprocess a previously buffered request belonging to another user, effectively hijacking that user's authenticated session. Exploitation requires high attack complexity due to narrow timing conditions — the attacker must race against the legitimate user's request lifecycle — and no privileges or user interaction are required. No public proof-of-concept code has been identified at this time (GitHub Advisory).
Successful exploitation results in high impact on confidentiality and integrity, with low impact on availability, as an attacker gains access to another user's authenticated session context and all associated capabilities (GitHub Advisory). This could expose sensitive business data processed through SAP NetWeaver (e.g., financial records, HR data, ERP transactions) and allow unauthorized actions to be performed on behalf of the hijacked user. The scope is limited to the affected component, but the breadth of SAP NetWeaver deployments in enterprise environments means the potential business impact is significant.
As of the publication date, there is no evidence of active in-the-wild exploitation, no public proof-of-concept, and no threat actor attribution (GitHub Advisory). The EPSS score is approximately 0.26% (18th percentile), indicating a low near-term probability of exploitation. The NVD SSVC assessment classifies exploitation as "none" and automatable as "no," reflecting the high attack complexity imposed by the required timing conditions. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
SAP has released a security note (SAP Note 3757002) addressing this vulnerability as part of the September 2026 SAP Security Patch Day; administrators should apply the relevant kernel patches for their affected versions immediately (GitHub Advisory). As interim workarounds, organizations should implement network-level controls to restrict access to SAP NetWeaver application servers to trusted IP ranges, monitor for suspicious session activity and unexpected request reprocessing patterns, and review SAP Security Patch Day guidance at the official SAP portal. Prioritize patching systems exposed to untrusted networks or the internet.
The vulnerability was covered as part of SAP's September 2026 Security Patch Day, which addressed 19 new vulnerabilities, with multiple security outlets highlighting the session hijacking risk in enterprise ERP environments (Onapsis Blog, GBHackers, CyberSecurityNews). SecurityBridge and RedRays also published patch day summaries noting the authentication bypass nature of the flaw (SecurityBridge, RedRays). Community sentiment reflects moderate concern given the unauthenticated attack vector, tempered by the high attack complexity required for successful exploitation.
ソース: このレポートは AI を使用して生成されました
無料の脆弱性評価
9つのセキュリティドメインにわたるクラウドセキュリティプラクティスを評価して、リスクレベルをベンチマークし、防御のギャップを特定します。
パーソナライズされたデモを見る
"私が今まで見た中で最高のユーザーエクスペリエンスは、クラウドワークロードを完全に可視化します。"
"Wiz を使えば、クラウド環境で何が起こっているかを 1 つの画面で確認することができます"
"Wizが何かを重要視した場合、それは実際に重要であることを私たちは知っています。"