Junglewise Threat Intelligence

CVE-2026-76968: SAP Web Dispatcher information disclosure

CVE-2026-76968 · Severity: medium · CVSS 6.5 · Published 2026-09-08

Vendors: SAP.

Executive brief

SAP Web Dispatcher, Internet Communication Manager, and SAP Content Server allow authenticated attackers with low privileges to access administrative functions and view sensitive system information. An attacker with a standard user account can bypass access controls to retrieve confidential system state details that could enable further attacks on the SAP environment.

Technical details

This is an information disclosure vulnerability affecting SAP's web communication components. An authenticated attacker with low-privilege credentials can access administrative functionality and retrieve sensitive system state information through improper access controls. The vulnerability requires prior authentication but does not require elevated privileges. The disclosed information could facilitate reconnaissance for subsequent attacks, though the vulnerability itself does not enable code execution, data modification, or service disruption. A patch is available via SAP Security Note 3750721 published on 2026-09-08 as part of SAP's regular Security Patch Day.

Affected products

  • SAP Web Dispatcher
  • SAP Internet Communication Manager
  • SAP Content Server

Timeline

  • 2026-09-08: disclosed: Published as part of SAP Security Patch Day
  • 2026-09-08: patched: SAP Security Note 3750721 available

References