CVE-2026-27685: Insecure Deserialization in SAP NetWeaver Enterprise Portal Administration
SAP NetWeaver Enterprise Portal Administration is vulnerable if a privileged user uploads untrusted or malicious content that, upon deserialization, could result in a high impact on the confidentiality, integrity, and availability of the host system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-27685?
CVE-2026-27685 is classified as a high severity vulnerability due to its potential impact on confidentiality, integrity, and availability.
How do I fix CVE-2026-27685?
To fix CVE-2026-27685, ensure that only trusted content is uploaded by privileged users and implement proper input validation mechanisms.
What causes CVE-2026-27685?
CVE-2026-27685 is caused by insecure deserialization of untrusted content in SAP NetWeaver Enterprise Portal Administration.
Who is affected by CVE-2026-27685?
CVE-2026-27685 affects users of SAP NetWeaver Enterprise Portal Administration who allow privileged users to upload content.
What are the potential consequences of CVE-2026-27685?
The potential consequences of CVE-2026-27685 include unauthorized access, data breaches, and system compromise due to deserialization of malicious content.