critical2026-09-08SAP GUI for JavaCVE-2026-66768

Improper Access Control in SAP GUI for Java

SAP GUI for Java

Our Take

CVSS 9.0 on a client-side component is unusual. The "after user interaction" qualifier drops this slightly below the zero-click criticals above — it requires the victim to open a malicious session or file. SAP GUI for Java is widely deployed in environments avoiding Windows SAP GUI. Update the client and track deployment completion.

Vulnerability Detail

Trust level policy not correctly enforced for certain functions in SAP GUI for Java. A low-privileged attacker could gain unauthorized access or command execution after user interaction with a crafted payload.

Patch Action

Update SAP GUI for Java to the patched version from SAP Note 3781729. Requires end-user client update — coordinate with desktop support.

Affected Versions

BC-FES-JAV 8.10

Patch Info

Priority

🔴 Patch immediately

CVSS Score

9

SAP Note

3781729

CVE

CVE-2026-66768

Published

2026-09-08

← All patches