Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.0
CVE-2026-66768: SAP GUI for Java may let low‑privileged attackers run commands
CVE-2026-66768 · published 19 days ago
Summary
The SAP GUI for Java client does not correctly check the trust level of functions it receives from a connected SAP system. A user with limited rights could trick the backend into causing the client to execute commands on the end‑user’s computer, potentially exposing data or disrupting operations. Install the latest SAP patches and limit which backend systems can communicate with the GUI to mitigate the risk.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| sap_se | sap netweaver (sap gui for java) | BC-FES-JAV 8.10 |
Original advisory text
Improper Access Control in SAP NetWeaver (SAP GUI for Java)
SAP GUI for Java does not correctly enforce the trust level policy for certain functions invoked from a connected backend system. A low-privileged attacker could exploit this weakness by manipulating a connected backend system to trigger affected functionality. This could allow arbitrary command execution on the victim's machine, leading to a high impact on the confidentiality, integrity, and availability of the affected system.
Severity
9.0
Critical
CVSS 3.1: 9.0 (MITRE)
Exploitation
EPSS <1%
Type
CWE-807Reliance on Untrusted Inputs in a Security Decision
Timeline
Published8 Sep 2026
Updated27 Sep 2026
First seen8 Sep 2026
Track software like this
Free during beta