SAPCVE-2026-66767
SAP NetWeaver Application Server for ABAP and ABAP Platform: integer underflow
High7.7CVE-2026-66767 · Published Sep 8, 2026 · updated Sep 9, 2026
SAP NetWeaver Application Server for ABAP and ABAP Platform allows an unauthenticated user to send a specially crafted packet that triggers reprocessing of a previously buffered user request, potentially hijacking another user's session under narrow timing conditions. Successful exploitation could result in high impact on confidentiality and integrity, with low impact on availability of the application.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| SAP NetWeaver Application Server for ABAP and ABAP Platform Product | <= KRNL64NUC 7.22 | No fix yet |
| <= 7.22EXT | No fix yet | |
| <= KRNL64UC 7.22 | No fix yet | |
| <= 7.53 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-191
More SAP advisories
All SAP| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 8 | SAP NetWeaver and ABAP Platform: missing authorization | Medium4.3 | No fix yet |
| Sep 8 | SAP NetWeaver Business Client: code execution | High7.8 | No fix yet |
| Sep 8 | SAP Web Dispatcher, Internet: information disclosure | Medium6.5 | No fix yet |
| Sep 8 | SAP Cloud Application Programming Model (CAP): weakly protected credentials | Critical9.4 | No fix yet |
| Sep 8 | SAP Manufacturing Integration and Intelligence: server-side request forgery | Medium6.5 | No fix yet |
| Sep 8 | SAP UI5 does not sufficiently validate the parent frame's origin against the... | Medium4.3 | No fix yet |