CVE-2026-76968
Received Received - Intake

SAP Web Dispatcher Information Disclosure via Admin Interface

Vulnerability report for CVE-2026-76968, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-08

Assigner: SAP SE

Description

SAP Web Dispatcher, Internet Communication Manager and SAP Content Server allows an authenticated low-privileged attacker to access certain administrative functionality or interface and obtain sensitive information about the system state, resulting in information disclosure. This disclosed information could potentially be used to facilitate further attacks. This vulnerability has a high impact on the confidentiality of the application, with no impact on integrity or availability.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-08
Generated
2026-09-08
AI Q&A
2026-09-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
sap web_dispatcher *
sap internet_communication_manager *
sap content_server *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-497 The product does not properly prevent sensitive system-level information from being accessed by unauthorized actors who do not have the same level of access to the underlying system as the product does.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

SAP Web Dispatcher, Internet Communication Manager and SAP Content Server have a vulnerability where an authenticated low-privileged attacker can access administrative functions or interfaces. This allows them to obtain sensitive system state information, which could be used for further attacks. The impact is primarily on confidentiality.

Impact Analysis

This vulnerability could allow attackers to gather sensitive system information, potentially leading to further attacks. The main risk is unauthorized access to confidential data, which could compromise system security and user privacy.

Compliance Impact

This vulnerability could lead to unauthorized disclosure of sensitive data, violating compliance requirements under GDPR and HIPAA. Organizations may face legal penalties, reputational damage, and loss of trust due to data breaches.

Mitigation Strategies

Apply the latest security patches from SAP as referenced in SAP Note 3750721. Ensure authentication requirements are enforced and restrict access to administrative interfaces. Monitor system logs for unusual activity and limit privileges for authenticated users.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-76968. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart