Junglewise Threat Intelligence

CVE-2026-76963: SAP NetWeaver authorization bypass in Application Server ABAP

CVE-2026-76963 · Severity: medium · CVSS 4.3 · Published 2026-09-08

Technologies: SAP NetWeaver. Vendors: SAP.

Executive brief

SAP NetWeaver and ABAP Platform are enterprise application servers used to run critical business processes and host sensitive configuration data. A missing authorization check allows authenticated users to access confidential system settings and internal architecture details they should not be able to view, potentially aiding attackers in planning further intrusions or configuration-based exploits.

Technical details

The vulnerability is a missing authorization check in the Application Server ABAP component of SAP NetWeaver and ABAP Platform. An authenticated attacker can bypass access controls to view sensitive system configuration information and internal system details. No privilege escalation or code execution is possible; the impact is limited to unauthorized disclosure of security-relevant settings (low confidentiality impact). The attack requires prior authentication and is not known to be exploited in the wild. SAP has issued security patches via their regular Security Patch Day process.

Affected products

  • SAP NetWeaver
  • SAP ABAP Platform

Timeline

  • 2026-09-08: disclosed

References

Related threats