CVE-2026-23687: XML Signature Wrapping in SAP NetWeaver AS ABAP and ABAP Platform
SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated attacker with normal privileges to obtain a valid signed message and send modified signed XML documents to the verifier. This may result in acceptance of tampered identity information, unauthorized access to sensitive user data and potential disruption of normal system usage.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-23687?
CVE-2026-23687 is classified as a critical vulnerability due to its potential impact on the integrity of signed XML documents.
How do I fix CVE-2026-23687?
To address CVE-2026-23687, apply the latest security patches provided by SAP for the affected NetWeaver Application Server ABAP and ABAP Platform.
Who is affected by CVE-2026-23687?
CVE-2026-23687 affects users of SAP NetWeaver Application Server ABAP and SAP ABAP Platform who have normal privileges.
What can an attacker do with CVE-2026-23687?
An authenticated attacker can exploit CVE-2026-23687 to send modified signed XML documents to the verifier, potentially compromising the integrity of the system.
Is authentication required to exploit CVE-2026-23687?
Yes, CVE-2026-23687 requires that the attacker is authenticated with normal privileges to exploit this vulnerability.