CVE-2026-66767: Memory Corruption vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform
SAP NetWeaver Application Server for ABAP and ABAP Platform allows an unauthenticated user to send a specially crafted packet that triggers reprocessing of a previously buffered user request, potentially hijacking another user's session under narrow timing conditions. Successful exploitation could result in high impact on confidentiality and integrity, with low impact on availability of the application.
Affected Software
Event History
Frequently Asked Questions
Does exploitation require authentication or user interaction?
No. An unauthenticated attacker can send a specially crafted packet, and no user interaction is required.
What conditions are required for a successful attack?
The attack depends on reprocessing a previously buffered user request and succeeds only under narrow timing conditions. The attack complexity is rated high.
What could an attacker achieve if exploitation succeeds?
Successful exploitation may allow the attacker to hijack another user's session. The stated impact is high for confidentiality and integrity and low for availability.