Deserialization flaw allows local code execution in SAP NetWeaver Business Client
AI analysis
SAP NetWeaver Business Client does not sufficiently validate certain locally stored data that it processes at application startup, a flaw classified as CWE-502 (deserialization of untrusted data). An attacker with low privileges on the local system can replace this data with specially crafted content, and when the application is next launched the crafted content is processed with no further user interaction required. Successful exploitation results in arbitrary code execution in the context of the logged-on user, with high impact on the confidentiality, integrity, and availability of the application. Any organization running the SAP NetWeaver Business Client desktop application is affected, and fixes were delivered as part of SAP's September 2026 Security Patch Day. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known, and EPSS currently estimates only a 0.2% probability of exploitation within 30 days.
What to do: Apply the SAP security patch released with the September 2026 Patch Day to all systems running SAP NetWeaver Business Client, checking SAP's advisory for the specific affected and corrected releases. Because exploitation requires low-privileged local access, limit write access to the application's locally stored data/configuration locations and maintain endpoint hardening on workstations running the client. No workarounds are described in the available data, so prompt patching is the primary remediation.
Affected
| SAP NetWeaver Business Client | — |
Estimated exposure
large≈100,000–1,000,000 enterprise desktop installations worldwide (estimate) — SAP NetWeaver Business Client is the desktop client UI for SAP's widely deployed NetWeaver-based business applications across SAP's global enterprise customer base, which plausibly puts the install base in the hundreds of thousands of…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
SAP NetWeaver Business Client does not perform sufficient validation when processing certain locally stored data during application startup. An attacker with low privileges on the local system could replace this data with specially crafted content. When the application is next launched, the crafted content is processed and could lead to arbitrary code execution in the context of the user. This results in a high impact on confidentiality, integrity and availability of the application.