critical2026-09-08SAP GUI for JavaCVE-2026-66768
Improper Access Control in SAP GUI for Java
SAP GUI for Java
Our Take
CVSS 9.0 on a client-side component is unusual. The "after user interaction" qualifier drops this slightly below the zero-click criticals above — it requires the victim to open a malicious session or file. SAP GUI for Java is widely deployed in environments avoiding Windows SAP GUI. Update the client and track deployment completion.
Vulnerability Detail
Trust level policy not correctly enforced for certain functions in SAP GUI for Java. A low-privileged attacker could gain unauthorized access or command execution after user interaction with a crafted payload.
Patch Action
Update SAP GUI for Java to the patched version from SAP Note 3781729. Requires end-user client update — coordinate with desktop support.
Affected Versions
BC-FES-JAV 8.10
Patch Info