Code Injection Vulnerability in SAP NetWeaver Application Server Java
CVE-2026-27674
6.1MEDIUM
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 14 April 2026
What is CVE-2026-27674?
A code injection vulnerability exists in SAP NetWeaver Application Server Java (Web Dynpro Java) that allows unauthenticated attackers to inject malicious input. This crafted input is processed by the application, causing it to execute attacker-controlled content when accessed by a victim. Such exploitation can lead to the execution of arbitrary client-side code, severely compromising the confidentiality and integrity of affected applications.
Affected Version(s)
SAP NetWeaver Application Server Java (Web Dynpro Java) WD-RUNTIME 7.50