---
id: CVE-2026-66767
title: >-
  SAP NetWeaver Application Server for ABAP and ABAP Platform allows an
  unauthenticated user to send a specially crafted packet that triggers
  reprocessing of a previously buffered user request, potentially hijacking
  another user's session …
summary: >-
  SAP NetWeaver Application Server for ABAP and ABAP Platform allows an
  unauthenticated user to send a specially crafted packet that triggers
  reprocessing of a previously buffered user request, potentially hijacking
  another user's session …
severity: high
cvss: 7.7
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L'
cwe:
  - CWE-191
vendor: SAP_SE
product: SAP NetWeaver Application Server for ABAP and ABAP Platform
affected:
  - sap_netweaver_application_server_for_abap_and_abap_platform KRNL64NUC 7.22
  - sap_netweaver_application_server_for_abap_and_abap_platform 7.22EXT
  - sap_netweaver_application_server_for_abap_and_abap_platform KRNL64UC 7.22
  - sap_netweaver_application_server_for_abap_and_abap_platform 7.53
  - sap_netweaver_application_server_for_abap_and_abap_platform 8.04
  - sap_netweaver_application_server_for_abap_and_abap_platform KERNEL 7.22
  - sap_netweaver_application_server_for_abap_and_abap_platform 7.54
  - sap_netweaver_application_server_for_abap_and_abap_platform 7.77
  - sap_netweaver_application_server_for_abap_and_abap_platform 7.93
  - sap_netweaver_application_server_for_abap_and_abap_platform 9.16
  - sap_netweaver_application_server_for_abap_and_abap_platform 9.18
  - sap_netweaver_application_server_for_abap_and_abap_platform 9.19
  - sap_netweaver_application_server_for_abap_and_abap_platform 9.20
published: '2026-09-08'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T05:17:27.420'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-66767'
references:
  - url: 'https://me.sap.com/notes/3757002'
    label: cna@sap.com
  - url: 'https://url.sap/sapsecuritypatchday'
    label: cna@sap.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-08T09:58:18.672335Z'
epss: 0.0026
epssPercentile: 0.18088
ingestedAt: '2026-09-08T15:33:26.981Z'
---

## Overview

SAP NetWeaver Application Server for ABAP and ABAP Platform allows an unauthenticated user to send a specially crafted packet that triggers reprocessing of a previously buffered user request, potentially hijacking another user's session under narrow timing conditions. Successful exploitation could result in high impact on confidentiality and integrity, with low impact on availability of the application.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
