{"id":"CVE-2026-66768","title":"SAP GUI for Java does not correctly enforce the trust level policy for certain functions invoked from a connected backend system","summary":"SAP GUI for Java does not correctly enforce the trust level policy for certain functions invoked from a connected backend system. A low-privileged attacker could exploit this weakness by manipulating a connected backend system to trigger…","severity":"critical","cvss":9,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H","cwe":["CWE-807"],"vendor":"SAP_SE","product":"SAP NetWeaver (SAP GUI for Java)","affected":["sap_netweaver_sap_gui_for_java BC-FES-JAV 8.10"],"published":"2026-09-08","updated":"2026-09-09","sourceUpdated":"2026-09-09T05:17:27.537","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-66768","references":[{"url":"https://me.sap.com/notes/3781729","label":"cna@sap.com"},{"url":"https://url.sap/sapsecuritypatchday","label":"cna@sap.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-09-08T09:59:43.809998Z"},"epss":0.00318,"epssPercentile":0.24957,"ingestedAt":"2026-09-08T15:33:26.981Z","slug":"CVE-2026-66768","body":"## Overview\n\nSAP GUI for Java does not correctly enforce the trust level policy for certain functions invoked from a connected backend system. A low-privileged attacker could exploit this weakness by manipulating a connected backend system to trigger affected functionality. This could allow arbitrary command execution on the victim's machine, leading to a high impact on the confidentiality, integrity, and availability of the affected system.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":50,"depthScoreParts":{"impact":49.5,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}