CVE-2026-27674 MEDIUM

CVE-2026-27674: Code Injection vulnerability in SAP NetWeaver Application Server Java (Web Dynpro Java)

Vendor Sap_Se
Product SAP NetWeaver Application Server Java (Web Dynpro Java)
Weakness CWE-94 · Code injection
Published April 14, 2026
Last update April 15, 2026

CVSS base score

6.1/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction Required
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

What the vulnerability does

Description

Due to a Code Injection vulnerability in SAP NetWeaver Application Server Java (Web Dynpro Java), an unauthenticated attacker could supply crafted input that is interpreted by the application and causes it to reference attacker-controlled content. If a victim accesses the affected functionality, that attacker-controlled content could be executed in the victim�s browser, potentially resulting in session compromise. This could allow the attacker to execute arbitrary client-side code, impacting the confidentiality and integrity of the application, with no impact to availability.

Key dates

Disclosure timeline

April 14, 2026 CVE published
April 15, 2026 Record updated