Session Hijacking Vulnerability in SAP NetWeaver Application Server for ABAP
CVE-2026-66767
7.7HIGH
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 8 September 2026
What is CVE-2026-66767?
An unauthenticated attacker can exploit a vulnerability in SAP NetWeaver Application Server for ABAP by sending a specially crafted packet designed to reprocess previously buffered user requests. This can lead to another user's session being hijacked under certain narrow timing conditions. Successful exploitation could severely compromise the confidentiality and integrity of user data while having a minimal effect on the system's availability.
Affected Version(s)
SAP NetWeaver Application Server for ABAP and ABAP Platform KRNL64NUC 7.22
SAP NetWeaver Application Server for ABAP and ABAP Platform 7.22EXT
SAP NetWeaver Application Server for ABAP and ABAP Platform KRNL64UC 7.22