XML Signature Wrapping in SAP NetWeaver AS ABAP and ABAP Platform
Summary
| CVE | CVE-2026-23687 |
|---|---|
| State | PUBLISHED |
| Assigner | sap |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-02-10 04:16:03 UTC |
| Updated | 2026-06-09 08:16:27 UTC |
| Description | SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated attacker with normal privileges to obtain a valid signed message and send modified signed XML documents to the verifier. This may result in acceptance of tampered identity information, unauthorized access to sensitive user data and potential disruption of normal system usage. |
Risk And Classification
Primary CVSS: v3.1 8.8 HIGH from [email protected]
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS: 0.000180000 probability, percentile 0.046450000 (date 2026-06-14)
Problem Types: CWE-347 | CWE-347 CWE-347: Improper Verification of Cryptographic Signature
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 8.8 | HIGH | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | CNA | CVSS | 8.8 | HIGH | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Sap | Sap Basis | 700 | All | All | All |
| Application | Sap | Sap Basis | 701 | All | All | All |
| Application | Sap | Sap Basis | 702 | All | All | All |
| Application | Sap | Sap Basis | 731 | All | All | All |
| Application | Sap | Sap Basis | 740 | All | All | All |
| Application | Sap | Sap Basis | 750 | All | All | All |
| Application | Sap | Sap Basis | 751 | All | All | All |
| Application | Sap | Sap Basis | 752 | All | All | All |
| Application | Sap | Sap Basis | 753 | All | All | All |
| Application | Sap | Sap Basis | 754 | All | All | All |
| Application | Sap | Sap Basis | 755 | All | All | All |
| Application | Sap | Sap Basis | 756 | All | All | All |
| Application | Sap | Sap Basis | 757 | All | All | All |
| Application | Sap | Sap Basis | 758 | All | All | All |
| Application | Sap | Sap Basis | 804 | All | All | All |
| Application | Sap | Sap Basis | 916 | All | All | All |
| Application | Sap | Sap Basis | 917 | All | All | All |
| Application | Sap | Sap Basis | 918 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| seclists.org/fulldisclosure/2026/Jun/1 | af854a3a-2127-422b-91ae-364da2661108 | seclists.org | |
| me.sap.com/notes/3697567 | [email protected] | me.sap.com | Permissions Required |
| url.sap/sapsecuritypatchday | [email protected] | url.sap | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.