CVE-2026-23686
Due to a CRLF Injection vulnerability in SAP NetWeaver Application Server Java, an authenticated attacker with administrative access could submit specially crafted content to the application.
Does this matter?
Lower severity and a low EPSS score (0.17%). Track it; it rarely justifies an emergency change on its own.
Description
Due to a CRLF Injection vulnerability in SAP NetWeaver Application Server Java, an authenticated attacker with administrative access could submit specially crafted content to the application. If processed by the application, this content enables injection of untrusted entries into generated configuration, allowing manipulation of application-controlled settings. Successful exploitation leads to a low impact on integrity, while confidentiality and availability remain unaffected.
- CVSS 3.1
- 3.4 LOWCVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:N/I:L/A:N
- EPSS
- 0.17% probability · 7th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-113, CWE-436
- Affected
- sap/netweaver application server java
- Source
- cna@sap.com
References
- https://me.sap.com/notes/3673213Permissions Required
- https://url.sap/sapsecuritypatchdayVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.