CVE-2026-27674 Details
Description
Due to a Code Injection vulnerability in SAP NetWeaver Application Server Java (Web Dynpro Java), an unauthenticated attacker could supply crafted input that is interpreted by the application and causes it to reference attacker-controlled content. If a victim accesses the affected functionality, that attacker-controlled content could be executed in the victim�s browser, potentially resulting in session compromise. This could allow the attacker to execute arbitrary client-side code, impacting the confidentiality and integrity of the application, with no impact to availability.
A code injection vulnerability has been identified in SAP NetWeaver Application Server Java, specifically within Web Dynpro Java. This vulnerability allows an unauthenticated attacker to send crafted input that the application interprets, potentially referencing attacker-controlled content. If a victim interacts with the affected functionality, the injected content could be executed in the victim's browser, leading to a session compromise. This exploitation could enable the attacker to execute arbitrary client-side code, thereby affecting the application's confidentiality and integrity, although there would be no impact on availability.
Users are advised to consult the SAP Security Notes for guidance on applying necessary patches. Security fixes for SAP NetWeaver products are typically included in support packages. For information on the latest SAP Security Patch Day, refer to the SAP Security Patch Day Bulletin.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 14, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://me.sap.com/notes/3719397 | [email protected] | Permissions Required |
| https://url.sap/sapsecuritypatchday | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-94 | Improper Control of Generation of Code ('Code Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| sap netweaver application server java | 7.50 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 3, 2026 | Initial Analysis | [email protected] |
| Apr 14, 2026 | New CVE Received | [email protected] |