Skip to content

Menu
  • Home
Menu

CVE-2026-66768 – Improper Access Control in SAP NetWeaver (SAP GUI for Java)

Posted on September 8, 2026
CVE ID :CVE-2026-66768

Published : Sept. 8, 2026, 12:11 a.m. | 44 minutes ago

Description :SAP GUI for Java does not correctly enforce the trust level policy for certain functions invoked from a connected backend system. A low-privileged attacker could exploit this weakness by manipulating a connected backend system to trigger affected functionality. This could allow arbitrary command execution on the victim’s machine, leading to a high impact on the confidentiality, integrity, and availability of the affected system.

Severity: 9.0 | CRITICAL

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

Post Views: 2

Site map

  • About Us
  • Privacy Policy
  • Terms & Conditions of Use
©2026 | Design: Newspaperly WordPress Theme