SAP Web Dispatcher/ICCM/CMS Authenticated Info Disclosure
CVE-2026-76968 Published on September 8, 2026
Information Disclosure vulnerability in SAP Web Dispatcher, Internet Communication Manager and SAP Content Server
SAP Web Dispatcher, Internet Communication Manager and SAP Content Server allows an authenticated low-privileged attacker to access certain administrative functionality or interface and obtain sensitive information about the system state, resulting in information disclosure. This disclosed information could potentially be used to facilitate further attacks. This vulnerability has a high impact on the confidentiality of the application, with no impact on integrity or availability.
Vulnerability Analysis
CVE-2026-76968 is exploitable with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality, with no impact on integrity and availability.
Weakness Type
Exposure of Sensitive System Information to an Unauthorized Control Sphere
The application does not properly prevent sensitive system-level information from being accessed by unauthorized actors who do not have the same level of access to the underlying system as the application does.
Products Associated with CVE-2026-76968
Want to know whenever a new CVE is published for SAP Web Dispatcher? stack.watch will email you.
Affected Versions
SAP_SE SAP Web Dispatcher, Internet Communication Manager and SAP Content Server:- Version KRNL64NUC 7.22 is affected.
- Version 7.22EXT is affected.
- Version KRNL64UC 7.22 is affected.
- Version 7.53 is affected.
- Version WEBDISP 7.22_EXT is affected.
- Version 7.54 is affected.
- Version 7.77 is affected.
- Version 7.93 is affected.
- Version 9.16 is affected.
- Version CONTSERV 7.53 is affected.
- Version KERNEL 7.22 is affected.
- Version 9.18 is affected.
- Version 9.19 is affected.
- Version 9.20 is affected.