Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 08 Sep 2026 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SAP NetWeaver Business Client does not perform sufficient validation when processing certain locally stored data during application startup. An attacker with low privileges on the local system could replace this data with specially crafted content. When the application is next launched, the crafted content is processed and could lead to arbitrary code execution in the context of the user. This results in a high impact on confidentiality, integrity and availability of the application. | |
| Title | Insecure Deserialization in SAP NetWeaver Business Client | |
| Weaknesses | CWE-502 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: sap
Published:
Updated: 2026-09-08T00:12:32.552Z
Reserved: 2026-08-20T05:15:36.824Z
Link: CVE-2026-76967
No data.
Status : Received
Published: 2026-09-08T01:17:55.170
Modified: 2026-09-08T01:17:55.170
Link: CVE-2026-76967
No data.
OpenCVE Enrichment
Updated: 2026-09-08T01:30:06Z