SAPCVE-2026-76968
SAP Web Dispatcher, Internet: information disclosure
Medium6.5CVE-2026-76968 · Published Sep 8, 2026
SAP Web Dispatcher, Internet Communication Manager and SAP Content Server allows an authenticated low-privileged attacker to access certain administrative functionality or interface and obtain sensitive information about the system state, resulting in information disclosure. This disclosed information could potentially be used to facilitate further attacks. This vulnerability has a high impact on the confidentiality of the application, with no impact on integrity or availability.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| SAP Web Dispatcher, Internet Communication Manager and SAP Content Server Product | <= KRNL64NUC 7.22 | No fix yet |
| <= 7.22EXT | No fix yet | |
| <= KRNL64UC 7.22 | No fix yet | |
| <= 7.53 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-497
More SAP advisories
All SAP| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 8 | SAP NetWeaver and ABAP Platform: missing authorization | Medium4.3 | No fix yet |
| Sep 8 | SAP NetWeaver Business Client: code execution | High7.8 | No fix yet |
| Sep 8 | SAP Cloud Application Programming Model (CAP): weakly protected credentials | Critical9.4 | No fix yet |
| Sep 8 | SAP Manufacturing Integration and Intelligence: server-side request forgery | Medium6.5 | No fix yet |
| Sep 8 | SAP UI5 does not sufficiently validate the parent frame's origin against the... | Medium4.3 | No fix yet |
| Sep 8 | SAP Integration Suite: resource exhaustion | High8.5 | No fix yet |