CVE-2026-66767
Received Received - Intake

Session Hijacking in SAP NetWeaver Application Server

Vulnerability report for CVE-2026-66767, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-08

Assigner: SAP SE

Description

SAP NetWeaver Application Server for ABAP and ABAP Platform allows an unauthenticated user to send a specially crafted packet that triggers reprocessing of a previously buffered user request, potentially hijacking another user's session under narrow timing conditions. Successful exploitation could result in high impact on confidentiality and integrity, with low impact on availability of the application.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-08
Generated
2026-09-08
AI Q&A
2026-09-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
sap netweaver_application_server_for_abap *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-191 The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform allows an unauthenticated attacker to send a specially crafted packet that reprocesses a previously buffered user request. This could hijack another user's session under very specific timing conditions.

Detection Guidance

Detection of this vulnerability requires monitoring SAP NetWeaver Application Server for ABAP for unusual session activity or packet reprocessing. Check SAP logs for repeated session requests or unexpected user actions. Use network monitoring tools to inspect for crafted packets triggering session hijacking attempts.

Impact Analysis

Successful exploitation could lead to high impact on confidentiality and integrity of data, meaning sensitive information could be accessed or altered. Availability impact is low, so the system itself is unlikely to crash.

Compliance Impact

This vulnerability could compromise confidentiality and integrity of data, which are key requirements under GDPR and HIPAA. Non-compliance risks include legal penalties, reputational damage, and loss of trust.

Mitigation Strategies

Apply the official SAP security note 3757002 immediately to patch the vulnerability. Monitor network traffic for unusual session reprocessing patterns and restrict unauthenticated access to the affected SAP NetWeaver components.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-66767. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart