CVE-2026-23685

Due to a Deserialization vulnerability in SAP NetWeaver (JMS service), an attacker authenticated as an administrator with local access could submit specially crafted content to the server. If processed by the application, this content could trigger unintended behavior during internal logic execution, potentially causing a denial of service. Successful exploitation results in a high impact on availability, while confidentiality and integrity remain unaffected.
References
Link Resource
https://me.sap.com/notes/3687285 Permissions Required
https://url.sap/sapsecuritypatchday Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:sap:netweaver:7.50:*:*:*:java_as:*:*:*

History

17 Feb 2026, 16:04

Type Values Removed Values Added
Summary
  • (es) Debido a una vulnerabilidad de deserialización en SAP NetWeaver (servicio JMS), un atacante autenticado como administrador con acceso local podría enviar contenido especialmente diseñado al servidor. Si es procesado por la aplicación, este contenido podría desencadenar un comportamiento no deseado durante la ejecución de la lógica interna, causando potencialmente una denegación de servicio. La explotación exitosa resulta en un alto impacto en la disponibilidad, mientras que la confidencialidad y la integridad permanecen inafectadas.
CPE cpe:2.3:a:sap:netweaver:7.50:*:*:*:java_as:*:*:*
References () https://me.sap.com/notes/3687285 - () https://me.sap.com/notes/3687285 - Permissions Required
References () https://url.sap/sapsecuritypatchday - () https://url.sap/sapsecuritypatchday - Vendor Advisory
First Time Sap netweaver
Sap

10 Feb 2026, 04:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-10 04:16

Updated : 2026-02-17 16:04


NVD link : CVE-2026-23685

Mitre link : CVE-2026-23685

CVE.ORG link : CVE-2026-23685


JSON object : View

Products Affected

sap

  • netweaver
CWE
CWE-502

Deserialization of Untrusted Data