Junglewise Threat Intelligence

CVE-2026-66768: SAP GUI for Java trust level policy bypass

CVE-2026-66768 · Severity: critical · CVSS 9 · Published 2026-09-08

Vendors: SAP.

Executive brief

SAP GUI for Java is a desktop client that connects enterprise systems to SAP backends. The product fails to properly enforce security trust policies when executing functions from a connected backend system, allowing a low-privileged attacker who can manipulate a backend system to execute arbitrary commands on the victim's machine. This could result in full compromise of user workstations, exposing sensitive corporate data and enabling lateral movement within enterprise networks.

Technical details

SAP GUI for Java does not correctly enforce the trust level policy for certain functions invoked from a connected backend system, resulting in a policy bypass vulnerability. An attacker with low privileges on a backend system can manipulate function invocation to trigger affected functionality in the client. The vulnerability allows arbitrary command execution on the victim's machine, impacting confidentiality, integrity, and availability of the client system. The attack vector requires access to or control of a connected backend system, but does not require authentication or user interaction on the client side. Patches are available as part of SAP Security Patch Day releases.

Affected products

  • SAP GUI for Java

Timeline

  • 2026-09-08: disclosed
  • 2026-09-08: advisory

References