Session Hijacking Vulnerability in SAP NetWeaver Application Server for ABAP
CVE-2026-66767

7.7HIGH

What is CVE-2026-66767?

An unauthenticated attacker can exploit a vulnerability in SAP NetWeaver Application Server for ABAP by sending a specially crafted packet designed to reprocess previously buffered user requests. This can lead to another user's session being hijacked under certain narrow timing conditions. Successful exploitation could severely compromise the confidentiality and integrity of user data while having a minimal effect on the system's availability.

Affected Version(s)

SAP NetWeaver Application Server for ABAP and ABAP Platform KRNL64NUC 7.22

SAP NetWeaver Application Server for ABAP and ABAP Platform 7.22EXT

SAP NetWeaver Application Server for ABAP and ABAP Platform KRNL64UC 7.22

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.