cbcvebase.
CVE-2026-23686
published 2026-02-10

CVE-2026-23686: Due to a CRLF Injection vulnerability in SAP NetWeaver Application Server Java, an authenticated attacker with administrative access could submit specially…

PriorityP414low3.4CVSS 3.1
AVNACLPRHUIRSCCNILAN
EPSS
0.16%
5.9th percentile
Due to a CRLF Injection vulnerability in SAP NetWeaver Application Server Java, an authenticated attacker with administrative access could submit specially crafted content to the application. If processed by the application, this content enables injection of untrusted entries into generated configuration, allowing manipulation of application-controlled settings. Successful exploitation leads to a low impact on integrity, while confidentiality and availability remain unaffected.

Affected

2 ranges
VendorProductVersion rangeFixed in
sapnetweaver_application_server_java
sap_sesap_netweaver_application_server_java
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.