CVE-2026-76967

HIGH CVSS 3.1: 7.8 EPSS 0.22%
Updated Sep 09, 2026
SAP
Parameter Value
CVSS 7.8 (HIGH)
Type CWE-502 (Deserialization of Untrusted Data)
Vendor SAP
Public PoC No

SAP NetWeaver Business Client does not perform sufficient validation when processing certain locally stored data during application startup. An attacker with low privileges on the local system could replace this data with specially crafted content. When the application is next launched, the crafted content is processed and could lead to arbitrary code execution in the context of the user.

This results in a high impact on confidentiality, integrity and availability of the application.

Attack Parameters

Attack Vector
Local
Requires local access
Attack Complexity
Low
Easy to exploit
Privileges Required
Low
Basic privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
High
Complete data modification
Availability
High
Complete denial of service

CVSS Vector v3.1