Description
SAP GUI for Java does not correctly enforce the trust level policy for certain functions invoked from a connected backend system. A low-privileged attacker could exploit this weakness by manipulating a connected backend system to trigger affected functionality. This could allow arbitrary command execution on the victim's machine, leading to a high impact on the confidentiality, integrity, and availability of the affected system.
Published: 2026-09-08
Score: 9 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

SAP GUI for Java does not correctly enforce the trust level policy for certain functions invoked from a connected backend system. A low‑privileged attacker who can manipulate a backend can trigger the affected functionality and thereby execute arbitrary commands on the victim's machine. This allows the attacker to compromise confidentiality, integrity, and availability of the affected service.

Affected Systems

SAP NetWeaver, specifically the SAP GUI for Java component managed by SAP SE. No specific versions are listed, so all current releases of this product are considered vulnerable until a patch is applied.

Risk and Exploitability

The CVSS score of 9 indicates a very high severity. Because the exploitation requires only manipulation of a connected backend system, an attacker who can glean or inject commands into that backend with even low privileges can achieve remote command execution on the client. The EPSS score is not available and the threat is not listed in CISA KEV, meaning no known widespread exploitation yet, but the high CVSS warrants close attention. Mitigation requires prompt patching and strict access controls on backend connections.

Generated by OpenCVE AI on September 8, 2026 at 01:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the SAP security patch released in SAP note 3781729 to fix the trust level enforcement defect in SAP GUI for Java.
  • Verify that the SAP GUI client is configured to enforce the correct trust level settings and that no legacy settings permit unrestricted backend interaction.
  • Restrict backend systems that connect to SAP GUI clients to trusted, authorized users and networks to limit the attack surface.

Generated by OpenCVE AI on September 8, 2026 at 01:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 00:45:00 +0000

Type Values Removed Values Added
Description SAP GUI for Java does not correctly enforce the trust level policy for certain functions invoked from a connected backend system. A low-privileged attacker could exploit this weakness by manipulating a connected backend system to trigger affected functionality. This could allow arbitrary command execution on the victim's machine, leading to a high impact on the confidentiality, integrity, and availability of the affected system.
Title Improper Access Control in SAP NetWeaver (SAP GUI for Java)
Weaknesses CWE-807
References
Metrics cvssV3_1

{'score': 9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published:

Updated: 2026-09-08T00:11:15.666Z

Reserved: 2026-07-27T17:33:40.733Z

Link: CVE-2026-66768

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-08T01:17:52.113

Modified: 2026-09-08T01:17:52.113

Link: CVE-2026-66768

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T01:30:06Z

Weaknesses
  • CWE-807

    Reliance on Untrusted Inputs in a Security Decision