Unauthenticated Reprocessing Packet Allows Session Hijack in SAP NetWeaver ABAP
CVE-2026-66767 Published on September 8, 2026
Memory Corruption vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform
SAP NetWeaver Application Server for ABAP and ABAP Platform allows an unauthenticated user to send a specially crafted packet that triggers reprocessing of a previously buffered user request, potentially hijacking another user's session under narrow timing conditions. Successful exploitation could result in high impact on confidentiality and integrity, with low impact on availability of the application.
Vulnerability Analysis
CVE-2026-66767 can be exploited with network access, and does not require authorization privileges or user interaction. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality and integrity, and a small impact on availability.
Weakness Type
What is an Integer underflow Vulnerability?
The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result. This can happen in signed and unsigned cases.
CVE-2026-66767 has been classified to as an Integer underflow vulnerability or weakness.
Products Associated with CVE-2026-66767
Want to know whenever a new CVE is published for SAP Netweaver Application Server Abap? stack.watch will email you.
Affected Versions
SAP_SE SAP NetWeaver Application Server for ABAP and ABAP Platform:- Version KRNL64NUC 7.22 is affected.
- Version 7.22EXT is affected.
- Version KRNL64UC 7.22 is affected.
- Version 7.53 is affected.
- Version 8.04 is affected.
- Version KERNEL 7.22 is affected.
- Version 7.54 is affected.
- Version 7.77 is affected.
- Version 7.93 is affected.
- Version 9.16 is affected.
- Version 9.18 is affected.
- Version 9.19 is affected.
- Version 9.20 is affected.