ZeroHour

CVE-2026-23686

CVSS 3.1
3.4 low
EPSS
<1%p7
Published
()
Modified
Description

Due to a CRLF Injection vulnerability in SAP NetWeaver Application Server Java, an authenticated attacker with administrative access could submit specially crafted content to the application. If processed by the application, this content enables injection of untrusted entries into generated configuration, allowing manipulation of application-controlled settings. Successful exploitation leads to a low impact on integrity, while confidentiality and availability remain unaffected.

Vendors
sap
Products
netweaver application server java
Weakness
CWE-113, CWE-436
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:N/I:L/A:N

In the news

No ingested article mentions this CVE yet.