
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-23687 is an XML Signature Wrapping vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform, classified under CWE-347 (Improper Verification of Cryptographic Signature). An authenticated attacker with normal (low) privileges can obtain a valid signed XML message, modify it, and submit the tampered document to the verifier, which may accept the forged identity information. The vulnerability affects SAP Basis versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 758, 804, 916, 917, and 918. It was published on February 10, 2026, with a patch released on SAP Security Patch Day (February 2026). The CVSS v3.1 base score is 8.8 (High) (SAP Security Notes, Red Hat CVE).
The root cause is CWE-347 — Improper Verification of Cryptographic Signature — specifically an XML Signature Wrapping (XSW) flaw. In XSW attacks, an attacker intercepts a legitimately signed XML document, duplicates or repositions XML elements so that the signature still validates against the original (unmodified) portion while the application processes a different, attacker-controlled portion of the document. This allows the attacker to inject tampered identity assertions or other data that the verifier accepts as authentic. Exploitation requires only a valid authenticated session with normal user privileges and network access to the target SAP system; no elevated permissions or user interaction are needed (Onapsis Blog, Infinitsec Post, DarkWebInformer).
Successful exploitation can result in high impact to confidentiality, integrity, and availability of the affected SAP system. An attacker can forge identity information accepted by the verifier, enabling unauthorized access to sensitive user data, privilege escalation within the SAP environment, and potential disruption of normal system operations. Given SAP NetWeaver ABAP's role as a core enterprise platform, compromise could expose business-critical data and facilitate lateral movement across integrated SAP landscapes (SAP Security Notes, Onapsis Blog).
As of the time of reporting, there is no public proof-of-concept exploit and no confirmed evidence of in-the-wild exploitation (Red Hat CVE). The EPSS score is approximately 0.046%, indicating a currently low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. It is detectable via Qualys scanner (detection ID 87601) (Feedly Intelligence).
SAP released security patches for all affected SAP Basis versions (700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 758, 804, 916, 917, 918) as part of SAP Security Patch Day in February 2026. Organizations should apply the relevant SAP Security Notes immediately via the SAP Support Portal. As interim measures, implement network segmentation to restrict access to SAP NetWeaver systems, enforce the principle of least privilege for user accounts, and monitor for anomalous XML document submissions and unusual identity authentication patterns (SAP Security Notes, Onapsis Blog, SecurityBridge).
The vulnerability received coverage from multiple SAP security specialists. Onapsis and SecurityBridge both highlighted it in their February 2026 SAP Patch Day roundups, noting the high CVSS score and the risk of identity tampering in enterprise environments (Onapsis Blog, SecurityBridge). RedRays also covered the patch day, and DarkWebInformer flagged the XSW nature of the vulnerability on social media, emphasizing the potential for unauthorized access (DarkWebInformer, RedRays Blog). Community sentiment focused on the broad version range affected and the importance of prompt patching given SAP's prevalence in critical enterprise infrastructure.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."