SAPCVE-2026-76963
SAP NetWeaver and ABAP Platform: missing authorization
Medium4.3CVE-2026-76963 · Published Sep 8, 2026
Due to a missing authorization check in Application Server ABAP of SAP NetWeaver and ABAP Platform, an authenticated attacker could gain unauthorized access to sensitive system configuration information. Successful exploitation could result in exposure of security relevant settings and internal system details, resulting in low impact on confidentiality while integrity and availability remain unaffected.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| SAP NetWeaver and ABAP Platform Product | <= SAP_BASIS 700 | No fix yet |
| <= SAP_BASIS 701 | No fix yet | |
| <= SAP_BASIS 702 | No fix yet | |
| <= SAP_BASIS 731 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-862
More SAP advisories
All SAP| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 8 | SAP NetWeaver Business Client: code execution | High7.8 | No fix yet |
| Sep 8 | SAP Web Dispatcher, Internet: information disclosure | Medium6.5 | No fix yet |
| Sep 8 | SAP Cloud Application Programming Model (CAP): weakly protected credentials | Critical9.4 | No fix yet |
| Sep 8 | SAP Manufacturing Integration and Intelligence: server-side request forgery | Medium6.5 | No fix yet |
| Sep 8 | SAP UI5 does not sufficiently validate the parent frame's origin against the... | Medium4.3 | No fix yet |
| Sep 8 | SAP Integration Suite: resource exhaustion | High8.5 | No fix yet |