Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2020-26829
SAP NetWeaver Application Server Java vulnerability analysis and mitigation

Overview

SAP NetWeaver AS JAVA (P2P Cluster Communication), versions 7.11, 7.20, 7.30, 7.31, 7.40, and 7.50, contains a critical vulnerability (CVE-2020-26829) discovered in 2020. The vulnerability stems from missing authentication checks in the cluster communication system, which allows arbitrary connections from processes outside the cluster and network segment dedicated for internal cluster communication (NVD).

Technical details

The vulnerability exists in the Cluster Manager component introduced in SAP AS Java since version 7.10. The Cluster Manager listens by default on all interfaces on TCP ports following the pattern 50000+100i+20+5n, where 'i' refers to the JAVA instance number and 'n' is the node number within the cluster. The vulnerability has received a CVSS v3.1 base score of 10.0 CRITICAL (Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H), indicating the highest severity level (SecurityWeek, Onapsis).

Impact

The vulnerability allows an unauthenticated attacker to invoke functions typically restricted to system administrators. The potential impacts include installation of new trusted SSO providers, modification of database connection parameters, access to sensitive configuration information, and the ability to shut down the system completely. This could lead to full privileged access to the affected SAP system or result in a denial-of-service condition (SecurityWeek, NVD).

Exploitability

The vulnerability can be exploited by an unauthenticated attacker who can reach the Cluster Manager TCP port. The attack requires no user interaction and can be executed with low attack complexity. Due to missing authentication checks, the attacker can execute highly privileged actions without authentication (Onapsis).

Mitigation and workarounds

SAP has released security note 2974774 containing patches for the affected components. Organizations are strongly recommended to download and apply these security fixes to reduce business risks. The patches are available through the SAP Support Portal (SecurityWeek, Onapsis).

Additional resources


SourceThis report was generated using AI

Related SAP NetWeaver Application Server Java vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-44756CRITICAL10
  • SAP NetWeaver Application Server ABAP logoSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
NoYesSep 08, 2026
CVE-2026-58240CRITICAL9.8
  • SAP NetWeaver Application Server ABAP logoSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
NoYesSep 08, 2026
CVE-2026-40128CRITICAL9
  • SAP NetWeaver Application Server Java logoSAP NetWeaver Application Server Java
  • cpe:2.3:a:sap:netweaver_application_server_java
NoYesJun 09, 2026
CVE-2026-27674MEDIUM6.1
  • SAP NetWeaver Application Server Java logoSAP NetWeaver Application Server Java
  • cpe:2.3:a:sap:netweaver_application_server_java
NoYesApr 14, 2026
CVE-2026-23686LOW3.4
  • SAP NetWeaver Application Server Java logoSAP NetWeaver Application Server Java
  • cpe:2.3:a:sap:netweaver_application_server_java
NoYesFeb 10, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management