CVE-2026-66767: 
SAP NetWeaver Application Server ABAP 脆弱性の分析と軽減

概要

CVE-2026-66767 is a session hijacking vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform that allows an unauthenticated attacker to send a specially crafted packet triggering reprocessing of a previously buffered user request, potentially hijacking another user's session under narrow timing conditions. It was published on September 8, 2026, and affects multiple kernel versions including KRNL64NUC 7.22, KRNL64UC 7.22, KERNEL 7.22, 7.53, 7.54, 7.77, 7.93, 8.04, 9.16, 9.18, 9.19, and 9.20. The vulnerability carries a CVSS v3.1 base score of 7.7 (High) (GitHub Advisory).

技術的な詳細

The root cause is classified as CWE-191 (Integer Underflow / Wrap or Wraparound), where a subtraction operation produces a value below the minimum allowable integer, leading to incorrect buffer length calculations in the SAP kernel's request handling logic (GitHub Advisory). An unauthenticated attacker over the network can exploit this by sending a specially crafted network packet that causes the server to reprocess a previously buffered request belonging to another user, effectively hijacking that user's authenticated session. Exploitation requires high attack complexity due to narrow timing conditions — the attacker must race against the legitimate user's request lifecycle — and no privileges or user interaction are required. No public proof-of-concept code has been identified at this time (GitHub Advisory).

影響

Successful exploitation results in high impact on confidentiality and integrity, with low impact on availability, as an attacker gains access to another user's authenticated session context and all associated capabilities (GitHub Advisory). This could expose sensitive business data processed through SAP NetWeaver (e.g., financial records, HR data, ERP transactions) and allow unauthorized actions to be performed on behalf of the hijacked user. The scope is limited to the affected component, but the breadth of SAP NetWeaver deployments in enterprise environments means the potential business impact is significant.

エクスプロイト可能性

As of the publication date, there is no evidence of active in-the-wild exploitation, no public proof-of-concept, and no threat actor attribution (GitHub Advisory). The EPSS score is approximately 0.26% (18th percentile), indicating a low near-term probability of exploitation. The NVD SSVC assessment classifies exploitation as "none" and automatable as "no," reflecting the high attack complexity imposed by the required timing conditions. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

エクスプロイテーションのステップ

  1. Reconnaissance: Identify internet-facing or network-accessible SAP NetWeaver Application Server for ABAP instances running affected kernel versions (KRNL64NUC 7.22, KRNL64UC 7.22, KERNEL 7.22, 7.53, 7.54, 7.77, 7.93, 8.04, 9.16, 9.18, 9.19, 9.20) using network scanning or SAP-specific discovery tools.
  2. Monitor target traffic: Observe or infer timing of legitimate user requests to the SAP NetWeaver server to identify windows when user requests are buffered server-side.
  3. Craft malicious packet: Construct a specially crafted network packet designed to trigger an integer underflow in the kernel's buffer length calculation, causing the server to reprocess a previously buffered user request.
  4. Time the attack: Send the crafted packet during the narrow timing window when a legitimate user's request is buffered, exploiting the race condition to cause the server to associate the attacker's connection with the victim's session.
  5. Session hijack: Upon successful exploitation, gain access to the victim user's authenticated session context, enabling unauthorized data access and transaction execution within the SAP environment (GitHub Advisory).

妥協の兆候

  • Network: Unexpected or malformed packets targeting SAP NetWeaver application server ports (e.g., 3200–3299 for DIAG, 8000/443 for HTTP/HTTPS) from unauthenticated sources; unusual connection patterns with rapid repeated requests.
  • Logs: SAP system logs (SM21) showing session ownership anomalies or unexpected session reuse; work process logs indicating request reprocessing events not initiated by the original user; ICM (Internet Communication Manager) logs showing unusual request buffering behavior.
  • Process: SAP work processes handling requests attributed to a user from an unexpected client IP address or connection; abrupt session context switches in application server traces.
  • Application: Unexpected user actions or transactions appearing in audit logs (SM20) that do not correlate with the legitimate user's activity timeline.

軽減策と回避策

SAP has released a security note (SAP Note 3757002) addressing this vulnerability as part of the September 2026 SAP Security Patch Day; administrators should apply the relevant kernel patches for their affected versions immediately (GitHub Advisory). As interim workarounds, organizations should implement network-level controls to restrict access to SAP NetWeaver application servers to trusted IP ranges, monitor for suspicious session activity and unexpected request reprocessing patterns, and review SAP Security Patch Day guidance at the official SAP portal. Prioritize patching systems exposed to untrusted networks or the internet.

コミュニティの反応

The vulnerability was covered as part of SAP's September 2026 Security Patch Day, which addressed 19 new vulnerabilities, with multiple security outlets highlighting the session hijacking risk in enterprise ERP environments (Onapsis Blog, GBHackers, CyberSecurityNews). SecurityBridge and RedRays also published patch day summaries noting the authentication bypass nature of the flaw (SecurityBridge, RedRays). Community sentiment reflects moderate concern given the unauthenticated attack vector, tempered by the high attack complexity required for successful exploitation.

関連情報


ソース: このレポートは AI を使用して生成されました

関連 SAP NetWeaver Application Server ABAP 脆弱 性:

CVE 識別子

重大度

スコア

テクノロジー

コンポーネント名

CISA KEV エクスプロイト

修正あり

公開日

CVE-2026-44756CRITICAL10
  • SAP NetWeaver Application Server ABAP logoSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
いいえはいSep 08, 2026
CVE-2026-58240CRITICAL9.8
  • SAP NetWeaver Application Server ABAP logoSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
いいえはいSep 08, 2026
CVE-2026-66767HIGH7.7
  • SAP NetWeaver Application Server ABAP logoSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
いいえはいSep 08, 2026
CVE-2026-66779MEDIUM6.3
  • SAP NetWeaver Application Server ABAP logoSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
いいえいいえAug 11, 2026
CVE-2026-58236MEDIUM5.5
  • SAP NetWeaver Application Server ABAP logoSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
いいえはいAug 11, 2026

無料の脆弱性評価

クラウドセキュリティポスチャーのベンチマーク

9つのセキュリティドメインにわたるクラウドセキュリティプラクティスを評価して、リスクレベルをベンチマークし、防御のギャップを特定します。

評価を依頼する

パーソナライズされたデモを見る

実際に Wiz を見てみませんか?​

"私が今まで見た中で最高のユーザーエクスペリエンスは、クラウドワークロードを完全に可視化します。"
デビッド・エストリックCISO (最高情報責任者)
"Wiz を使えば、クラウド環境で何が起こっているかを 1 つの画面で確認することができます"
アダム・フレッチャーチーフ・セキュリティ・オフィサー
"Wizが何かを重要視した場合、それは実際に重要であることを私たちは知っています。"
グレッグ・ポニャトフスキ脅威および脆弱性管理責任者