A critical trust-level enforcement failure in SAP GUI for Java (CVSS 9.0) allows a low-privileged attacker who controls a connected backend system to execute arbitrary commands on a victim's client machine.
What Is It
SAP GUI for Java does not correctly enforce its trust level policy for certain functions invoked from a connected backend system. An attacker with low privileges can manipulate a connected backend to trigger the affected functionality, resulting in arbitrary command execution on the victim's machine. SAP's CNA classifies the weakness as CWE-807 (reliance on untrusted inputs in a security decision) and assigns a CVSS 3.1 base score of 9.0 (CRITICAL), vector CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H.
Why It Matters
The vulnerability inverts the normal client-server trust relationship: instead of the backend being at risk, the SAP GUI client is. If an attacker compromises or otherwise gains influence over a backend, that system could serve as a launch point against workstations connecting to it, potentially extending a single backend foothold into client-side code execution across part of an organization's SAP user base.
The scoring reflects that. Scope is Changed; the impact crosses beyond the vulnerable component into the victim's operating system. Attack vector is Network with Low complexity and only Low privileges required. The single mitigating factor is User Interaction: a victim must connect to and interact with the malicious backend, which is routine behavior for SAP GUI users. Confidentiality, integrity, and availability impacts are all High.
What's Vulnerable
- Vendor: SAP SE
- Product: SAP NetWeaver (SAP GUI for Java)
- Affected version: BC-FES-JAV 8.10
- Default status: All other versions listed as unaffected
No CPE entries have been published for this CVE at the time of writing.
Patch Status
The CVE record currently carries NVD vulnStatus "Received," meaning NVD analysis is not yet complete. SAP has issued Security Note 3781729 covering this issue, released as part of SAP Security Patch Day. Administrators running SAP GUI for Java BC-FES-JAV 8.10 should consult that note and apply the vendor-supplied fix.
This CVE is not listed in the CISA Known Exploited Vulnerabilities catalog as of this writing, so no federal remediation deadline applies to it. That absence is not evidence that exploitation has not occurred; it means no in-the-wild exploitation has been confirmed and cataloged by CISA. Given the CVSS 9.0 score and the client-side blast radius, defenders should not treat non-listing as a reason to defer patching.
Sources
- SAP Security Note 3781729; https://me.sap.com/notes/3781729
- SAP Security Patch Day; https://url.sap/sapsecuritypatchday
- NVD, CVE-2026-66768 (source identifier: [email protected]), https://nvd.nist.gov/vuln/detail/CVE-2026-66768
- CISA Known Exploited Vulnerabilities Catalog; https://www.cisa.gov/known-exploited-vulnerabilities-catalog