Junglewise Threat Intelligence

CVE-2026-27674: SAP NetWeaver AS Java code injection in Web Dynpro Java

CVE-2026-27674 · Severity: medium · CVSS 6.1 · Published 2026-04-14

Technologies: SAP Netweaver Application Server Java. Vendors: SAP.

Executive brief

A vulnerability in SAP NetWeaver Application Server Java could allow an attacker to trick a user's browser into executing malicious code. This occurs when the application improperly handles user input within the Web Dynpro Java component. If successful, an attacker could compromise a user's session, potentially leading to unauthorized access to sensitive information or the ability to perform actions on the user's behalf.

Technical details

A code injection vulnerability (CWE-94) exists in the Web Dynpro Java component of SAP NetWeaver Application Server Java. The flaw stems from improper validation of user-supplied input, which allows an unauthenticated remote attacker to provide crafted content that the application subsequently references. When a victim interacts with the affected functionality, the attacker-controlled content is executed within the context of the victim's browser session. This can lead to session hijacking and the execution of arbitrary client-side scripts. The vulnerability has been identified in version 7.50, and SAP has released security notes to address the issue.

Affected products

  • SAP NetWeaver Application Server Java (Web Dynpro Java) 7.50

Timeline

  • 2026-04-13: disclosed
  • 2026-04-14: advisory

References

Related threats