{"api_version":"1","generated_at":"2026-09-08T02:54:45+00:00","cve":"CVE-2026-66767","urls":{"html":"https://cve.report/CVE-2026-66767","api":"https://cve.report/api/cve/CVE-2026-66767.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-66767","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-66767"},"summary":{"title":"Memory Corruption vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform","description":"SAP NetWeaver Application Server for ABAP and ABAP Platform allows an unauthenticated user to send a specially crafted packet that triggers reprocessing of a previously buffered user request, potentially hijacking another user's session under narrow timing conditions. Successful exploitation could result in high impact on confidentiality and integrity, with low impact on availability of the application.","state":"PUBLISHED","assigner":"sap","published_at":"2026-09-08 01:17:51","updated_at":"2026-09-08 01:17:51"},"problem_types":["CWE-191","CWE-191 CWE-191: Integer Underflow"],"metrics":[{"version":"3.1","source":"cna@sap.com","type":"Primary","score":"7.7","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","baseScore":7.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"LOW"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"7.7","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","data":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"LOW","baseScore":7.7,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","version":"3.1"}}],"references":[{"url":"https://me.sap.com/notes/3757002","name":"https://me.sap.com/notes/3757002","refsource":"cna@sap.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://url.sap/sapsecuritypatchday","name":"https://url.sap/sapsecuritypatchday","refsource":"cna@sap.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-66767","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-66767","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"SAP_SE","product":"SAP NetWeaver Application Server for ABAP and ABAP Platform","version":"affected KRNL64NUC 7.22","platforms":[]},{"source":"CNA","vendor":"SAP_SE","product":"SAP NetWeaver Application Server for ABAP and ABAP Platform","version":"affected 7.22EXT","platforms":[]},{"source":"CNA","vendor":"SAP_SE","product":"SAP NetWeaver Application Server for ABAP and ABAP Platform","version":"affected KRNL64UC 7.22","platforms":[]},{"source":"CNA","vendor":"SAP_SE","product":"SAP NetWeaver Application Server for ABAP and ABAP Platform","version":"affected 7.53","platforms":[]},{"source":"CNA","vendor":"SAP_SE","product":"SAP NetWeaver Application Server for ABAP and ABAP Platform","version":"affected 8.04","platforms":[]},{"source":"CNA","vendor":"SAP_SE","product":"SAP NetWeaver Application Server for ABAP and ABAP Platform","version":"affected KERNEL 7.22","platforms":[]},{"source":"CNA","vendor":"SAP_SE","product":"SAP NetWeaver Application Server for ABAP and ABAP Platform","version":"affected 7.54","platforms":[]},{"source":"CNA","vendor":"SAP_SE","product":"SAP NetWeaver Application Server for ABAP and ABAP Platform","version":"affected 7.77","platforms":[]},{"source":"CNA","vendor":"SAP_SE","product":"SAP NetWeaver Application Server for ABAP and ABAP Platform","version":"affected 7.93","platforms":[]},{"source":"CNA","vendor":"SAP_SE","product":"SAP NetWeaver Application Server for ABAP and ABAP Platform","version":"affected 9.16","platforms":[]},{"source":"CNA","vendor":"SAP_SE","product":"SAP NetWeaver Application Server for ABAP and ABAP Platform","version":"affected 9.18","platforms":[]},{"source":"CNA","vendor":"SAP_SE","product":"SAP NetWeaver Application Server for ABAP and ABAP Platform","version":"affected 9.19","platforms":[]},{"source":"CNA","vendor":"SAP_SE","product":"SAP NetWeaver Application Server for ABAP and ABAP Platform","version":"affected 9.20","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"SAP NetWeaver Application Server for ABAP and ABAP Platform","vendor":"SAP_SE","versions":[{"status":"affected","version":"KRNL64NUC 7.22"},{"status":"affected","version":"7.22EXT"},{"status":"affected","version":"KRNL64UC 7.22"},{"status":"affected","version":"7.53"},{"status":"affected","version":"8.04"},{"status":"affected","version":"KERNEL 7.22"},{"status":"affected","version":"7.54"},{"status":"affected","version":"7.77"},{"status":"affected","version":"7.93"},{"status":"affected","version":"9.16"},{"status":"affected","version":"9.18"},{"status":"affected","version":"9.19"},{"status":"affected","version":"9.20"}]}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>SAP NetWeaver Application Server for ABAP and ABAP Platform allows an unauthenticated user to send a specially crafted packet that triggers reprocessing of a previously buffered user request, potentially hijacking another user's session under narrow timing conditions. Successful exploitation could result in high impact on confidentiality and integrity, with low impact on availability of the application.</p>"}],"value":"SAP NetWeaver Application Server for ABAP and ABAP Platform allows an unauthenticated user to send a specially crafted packet that triggers reprocessing of a previously buffered user request, potentially hijacking another user's session under narrow timing conditions. Successful exploitation could result in high impact on confidentiality and integrity, with low impact on availability of the application."}],"metrics":[{"cvssV3_1":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"LOW","baseScore":7.7,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-191","description":"CWE-191: Integer Underflow","lang":"eng","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-09-08T00:11:06.906Z","orgId":"e4686d1a-f260-4930-ac4c-2f5c992778dd","shortName":"sap"},"references":[{"url":"https://me.sap.com/notes/3757002"},{"url":"https://url.sap/sapsecuritypatchday"}],"source":{"discovery":"UNKNOWN"},"title":"Memory Corruption vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform","x_generator":{"engine":"Vulnogram 1.0.5"}}},"cveMetadata":{"assignerOrgId":"e4686d1a-f260-4930-ac4c-2f5c992778dd","assignerShortName":"sap","cveId":"CVE-2026-66767","datePublished":"2026-09-08T00:11:06.906Z","dateReserved":"2026-07-27T17:33:40.733Z","dateUpdated":"2026-09-08T00:11:06.906Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-08 01:17:51","lastModifiedDate":"2026-09-08 01:17:51","problem_types":["CWE-191","CWE-191 CWE-191: Integer Underflow"],"metrics":{"cvssMetricV31":[{"source":"cna@sap.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","baseScore":7.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"LOW"},"exploitabilityScore":2.2,"impactScore":5.5}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"66767","Ordinal":"1","Title":"Memory Corruption vulnerability in SAP NetWeaver Application Ser","CVE":"CVE-2026-66767","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"66767","Ordinal":"1","NoteData":"SAP NetWeaver Application Server for ABAP and ABAP Platform allows an unauthenticated user to send a specially crafted packet that triggers reprocessing of a previously buffered user request, potentially hijacking another user's session under narrow timing conditions. Successful exploitation could result in high impact on confidentiality and integrity, with low impact on availability of the application.","Type":"Description","Title":"Memory Corruption vulnerability in SAP NetWeaver Application Ser"}]}}}