cbcvebase.
CVE-2026-66768
published 2026-09-08

CVE-2026-66768: SAP GUI for Java does not correctly enforce the trust level policy for certain functions invoked from a connected backend system. A low-privileged attacker…

PriorityP359critical9CVSS 3.1
AVNACLPRLUIRSCCHIHAH
EPSS
0.32%
24.5th percentile
SAP GUI for Java does not correctly enforce the trust level policy for certain functions invoked from a connected backend system. A low-privileged attacker could exploit this weakness by manipulating a connected backend system to trigger affected functionality. This could allow arbitrary command execution on the victim's machine, leading to a high impact on the confidentiality, integrity, and availability of the affected system.

Affected

1 ranges
VendorProductVersion rangeFixed in
sap_sesap_netweaver
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.