CVE-2026-23685 MEDIUM

CVE-2026-23685: Insecure Deserialization vulnerability in SAP NetWeaver (JMS service)

Vendor Sap_Se
Product SAP NetWeaver (JMS service)
Weakness CWE-502 · Unsafe deserialization
Published February 10, 2026
Last update February 10, 2026

CVSS base score

4.4/10
Attack vector Local
Attack complexity Low
Privileges required High
User interaction None
Confidentiality None
Integrity None

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H

What the vulnerability does

01Description

Due to a Deserialization vulnerability in SAP NetWeaver (JMS service), an attacker authenticated as an administrator with local access could submit specially crafted content to the server. If processed by the application, this content could trigger unintended behavior during internal logic execution, potentially causing a denial of service. Successful exploitation results in a high impact on availability, while confidentiality and integrity remain unaffected.

Key dates

02Disclosure timeline

February 10, 2026 CVE published
February 10, 2026 Record updated