CVE-2026-23687
SAP NetWeaver Application Server ABAP vulnerability analysis and mitigation

Overview

CVE-2026-23687 is an XML Signature Wrapping vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform, classified under CWE-347 (Improper Verification of Cryptographic Signature). An authenticated attacker with normal (low) privileges can obtain a valid signed XML message, modify it, and submit the tampered document to the verifier, which may accept the forged identity information. The vulnerability affects SAP Basis versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 758, 804, 916, 917, and 918. It was published on February 10, 2026, with a patch released on SAP Security Patch Day (February 2026). The CVSS v3.1 base score is 8.8 (High) (SAP Security Notes, Red Hat CVE).

Technical details

The root cause is CWE-347 — Improper Verification of Cryptographic Signature — specifically an XML Signature Wrapping (XSW) flaw. In XSW attacks, an attacker intercepts a legitimately signed XML document, duplicates or repositions XML elements so that the signature still validates against the original (unmodified) portion while the application processes a different, attacker-controlled portion of the document. This allows the attacker to inject tampered identity assertions or other data that the verifier accepts as authentic. Exploitation requires only a valid authenticated session with normal user privileges and network access to the target SAP system; no elevated permissions or user interaction are needed (Onapsis Blog, Infinitsec Post, DarkWebInformer).

Impact

Successful exploitation can result in high impact to confidentiality, integrity, and availability of the affected SAP system. An attacker can forge identity information accepted by the verifier, enabling unauthorized access to sensitive user data, privilege escalation within the SAP environment, and potential disruption of normal system operations. Given SAP NetWeaver ABAP's role as a core enterprise platform, compromise could expose business-critical data and facilitate lateral movement across integrated SAP landscapes (SAP Security Notes, Onapsis Blog).

Exploitability

As of the time of reporting, there is no public proof-of-concept exploit and no confirmed evidence of in-the-wild exploitation (Red Hat CVE). The EPSS score is approximately 0.046%, indicating a currently low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. It is detectable via Qualys scanner (detection ID 87601) (Feedly Intelligence).

Exploitation steps

  1. Reconnaissance: Identify SAP NetWeaver AS ABAP instances running affected SAP Basis versions (700–758, 804, 916–918) using network scanning or SAP landscape discovery tools.
  2. Obtain valid session: Authenticate to the target SAP system using any valid low-privileged user account.
  3. Capture a signed XML document: Interact with an SAP service or endpoint that issues signed XML messages (e.g., SAML assertions, XML-based web services) and capture a legitimately signed XML document.
  4. Craft the XSW payload: Duplicate or reposition XML elements within the captured document so that the digital signature still covers the original (benign) content, while inserting attacker-controlled identity or data elements that the application will process instead.
  5. Submit the tampered document: Send the modified XML document to the SAP verifier endpoint. Due to the improper signature verification, the system accepts the tampered document as valid.
  6. Achieve objective: The forged identity information is accepted, granting unauthorized access to sensitive data, elevated privileges, or the ability to impersonate other users within the SAP environment (Infinitsec Post, Onapsis Blog).

Indicators of compromise

  • Network: Unusual or repeated XML-based requests to SAP web service or SAML endpoints from authenticated low-privileged accounts; outbound connections from SAP application servers to unexpected hosts following XML processing.
  • Logs: SAP security audit log entries showing identity assertion changes or authentication events for users who did not initiate a login; anomalous XML parsing errors or signature validation warnings in SAP system logs (SM21, security audit log).
  • Application Behavior: Users accessing resources or transactions inconsistent with their assigned roles; unexpected session establishment under a different user identity than the one that authenticated.
  • File System: Unexpected changes to SAP configuration or user master data that correlate with XML service calls (DarkWebInformer, Onapsis Blog).

Mitigation and workarounds

SAP released security patches for all affected SAP Basis versions (700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 758, 804, 916, 917, 918) as part of SAP Security Patch Day in February 2026. Organizations should apply the relevant SAP Security Notes immediately via the SAP Support Portal. As interim measures, implement network segmentation to restrict access to SAP NetWeaver systems, enforce the principle of least privilege for user accounts, and monitor for anomalous XML document submissions and unusual identity authentication patterns (SAP Security Notes, Onapsis Blog, SecurityBridge).

Community reactions

The vulnerability received coverage from multiple SAP security specialists. Onapsis and SecurityBridge both highlighted it in their February 2026 SAP Patch Day roundups, noting the high CVSS score and the risk of identity tampering in enterprise environments (Onapsis Blog, SecurityBridge). RedRays also covered the patch day, and DarkWebInformer flagged the XSW nature of the vulnerability on social media, emphasizing the potential for unauthorized access (DarkWebInformer, RedRays Blog). Community sentiment focused on the broad version range affected and the importance of prompt patching given SAP's prevalence in critical enterprise infrastructure.

Additional resources


SourceThis report was generated using AI

Related SAP NetWeaver Application Server ABAP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-44756CRITICAL10
  • SAP NetWeaver Application Server ABAP logoSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
NoYesSep 08, 2026
CVE-2026-58240CRITICAL9.8
  • SAP NetWeaver Application Server ABAP logoSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
NoNoSep 08, 2026
CVE-2026-66767HIGH7.7
  • SAP NetWeaver Application Server ABAP logoSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
NoYesSep 08, 2026
CVE-2026-66779MEDIUM6.3
  • SAP NetWeaver Application Server ABAP logoSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
NoNoAug 11, 2026
CVE-2026-58236MEDIUM5.5
  • SAP NetWeaver Application Server ABAP logoSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
NoYesAug 11, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management