Skip to content
SAPCVE-2026-66768

SAP NetWeaver (SAP GUI for Java): untrusted input in a security decision

Critical9.0CVE-2026-66768 · Published Sep 8, 2026 · updated Sep 9, 2026

SAP GUI for Java does not correctly enforce the trust level policy for certain functions invoked from a connected backend system. A low-privileged attacker could exploit this weakness by manipulating a connected backend system to trigger affected functionality. This could allow arbitrary command execution on the victim's machine, leading to a high impact on the confidentiality, integrity, and availability of the affected system.

SAP advisory

Affected versions

PackageAffectedFixed in
SAP NetWeaver (SAP GUI for Java)
Product
<= BC-FES-JAV 8.10No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-807

More SAP advisories

All SAP
Advisory
SAP NetWeaver and ABAP Platform: missing authorization
Medium4.3Sep 8
SAP NetWeaver Business Client: code execution
High7.8Sep 8
SAP Web Dispatcher, Internet: information disclosure
Medium6.5Sep 8
SAP Cloud Application Programming Model (CAP): weakly protected credentials
Critical9.4Sep 8
SAP Manufacturing Integration and Intelligence: server-side request forgery
Medium6.5Sep 8
SAP UI5 does not sufficiently validate the parent frame's origin against the...
Medium4.3Sep 8

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.