medium2026-09-08SAP NetWeaver AS for ABAP / ABAP PlatformCVE-2026-76963

Missing Authorization Check in ABAP Platform

SAP NetWeaver AS for ABAP

Our Take

Missing authorization checks in the ABAP application layer are a recurring category. Patch it, and consider running SUIM or an authorization scanner to check for privilege anomalies in your system.

Vulnerability Detail

Authorization check bypass in Application Server ABAP. An authenticated attacker with minimal privileges could access unauthorized functionality.

Patch Action

Apply the patch per SAP Note 3772838. Verify affected ABAP Platform version in the official SAP Note.

Patch Info

CVSS Score

4.3

SAP Note

3772838

CVE

CVE-2026-76963

Published

2026-09-08

← All patches