← Back

CVE-2026-23686

nvd nist
Published: Feb 10, 2026Modified: Jun 17, 2026

JSON object

Loading...
3.4
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:N/I:L/A:N
Exploitability: 1.7 / Impact: 1.4
Source: NVD

Description

Due to a CRLF Injection vulnerability in SAP NetWeaver Application Server Java, an authenticated attacker with administrative access could submit specially crafted content to the application. If processed by the application, this content enables injection of untrusted entries into generated configuration, allowing manipulation of application-controlled settings. Successful exploitation leads to a low impact on integrity, while confidentiality and availability remain unaffected.

Affected (1)

1 product
Netweaver Application Server Java
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 7.50

References (2)

Source: cna@sap.com
Permissions Required
Source: cna@sap.com
Vendor Advisory

Timeline

No history available yet.