CVE-2026-76963

Summary

Due to a missing authorization check in Application Server ABAP of SAP NetWeaver and ABAP Platform, an authenticated attacker could gain unauthorized access to sensitive system configuration information. Successful exploitation could result in exposure of security relevant settings and internal system details, resulting in low impact on confidentiality while integrity and availability remain unaffected.

Affected Software

VendorProductVersion RangeStatus
SAP_SESAP NetWeaver and ABAP PlatformSAP_BASIS 700affected
SAP_SESAP NetWeaver and ABAP PlatformSAP_BASIS 701affected
SAP_SESAP NetWeaver and ABAP PlatformSAP_BASIS 702affected
SAP_SESAP NetWeaver and ABAP PlatformSAP_BASIS 731affected
SAP_SESAP NetWeaver and ABAP PlatformSAP_BASIS 740affected
SAP_SESAP NetWeaver and ABAP PlatformSAP_BASIS 750affected
SAP_SESAP NetWeaver and ABAP PlatformSAP_BASIS 751affected
SAP_SESAP NetWeaver and ABAP PlatformSAP_BASIS 752affected
SAP_SESAP NetWeaver and ABAP PlatformSAP_BASIS 753affected
SAP_SESAP NetWeaver and ABAP PlatformSAP_BASIS 754affected
SAP_SESAP NetWeaver and ABAP PlatformSAP_BASIS 755affected
SAP_SESAP NetWeaver and ABAP PlatformSAP_BASIS 756affected
SAP_SESAP NetWeaver and ABAP PlatformSAP_BASIS 757affected
SAP_SESAP NetWeaver and ABAP PlatformSAP_BASIS 758affected

Weaknesses

  • CWE-862: CWE-862: Missing Authorization

References