CVE-2026-66768

SAP GUI for Java does not correctly enforce the trust level policy for certain functions invoked from a connected backend system. A low-privileged attacker could exploit this weakness by manipulating a connected backend system to trigger affected functionality. This could allow arbitrary command execution on the victim's machine, leading to a high impact on the confidentiality, integrity, and availability of the affected system.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-08 01:17

Updated : 2026-09-09 05:17


NVD link : CVE-2026-66768

Mitre link : CVE-2026-66768

CVE.ORG link : CVE-2026-66768


JSON object : View

Products Affected

No product.

CWE
CWE-807

Reliance on Untrusted Inputs in a Security Decision