Enterprise & Mobile

Remote Code Execution

Code Injection Vulnerability in SAP NetWeaver Application Server Java (Web Dynpro Java)

This vulnerability allows a remote, unauthenticated attacker to execute arbitrary client-side code in the browsers of users accessing the affected SAP NetWeaver functionality.

6.1
/ 10
Medium
CVSS v3.1
ADVISORY ID
PS102
PUBLISHED
2026-06-03
CVE IDs
CVE-2026-27674
VENDORS
SAP
PUBLIC EXPLOIT
None indexed
CWE
CWE-94
PRODUCT
SAP NetWeaver AS Java (Web Dynpro Java)
CVSS VECTOR
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Abstract blurred background with dark tones and smooth gradient waves of blue, purple, and orange hues.
Summary

Overview

SAP NetWeaver Application Server Java (Web Dynpro Java) contains a Code Injection vulnerability that allows an unauthenticated attacker to supply crafted input that is interpreted by the application and causes it to reference attacker-controlled content. If a victim accesses the affected functionality, that attacker-controlled content could be executed in the victim's browser, potentially resulting in session compromise.

The root cause lies in insufficient input validation and sanitization within the Web Dynpro Java component. The application accepts user-controlled input and incorporates it into content that is later served to other users without properly neutralizing potentially malicious code or references. The vulnerability is classified under CWE-94 (Improper Control of Generation of Code / Code Injection). The attack is initiated remotely over the network and requires no authentication, though user interaction is necessary for the injected content to execute in the victim's browser context.

Vulnerability details

Vulnerability details

CVE-2026-27674
CWE-94
Medium | 6.1

SAP NetWeaver Application Server Java (Web Dynpro Java) contains a Code Injection vulnerability that allows an unauthenticated attacker to supply crafted input that is interpreted by the application and causes it to reference attacker-controlled content.

Auth:
None (remote, user interaction required)
Impact:
Limited data disclosure, limited data tampering; impact extends beyond the vulnerable component
Impact

What an attacker can do

This vulnerability allows a remote, unauthenticated attacker to execute arbitrary client-side code in the browsers of users accessing the affected SAP NetWeaver functionality. As a result: Session Compromise: Attacker-controlled code runs in the victim's browser context, potentially capturing session tokens, credentials, or other sensitive data. Credential Harvesting: Injected scripts can capture keystrokes, form submissions, or authentication tokens entered by the victim during the session. Persistent Attack Surface: If stored XSS is achievable, each subsequent user accessing the affected Web Dynpro component becomes a victim without further attacker interaction.

DISCLOSURE

Disclosure timeline

2026-01-29 Reported to Vendor

2026-02-23 CVE ID Reserved

2026-04-13 CVE Published

Credits

Chandru R – Payatu Security Consulting Pvt. Ltd.