CVE-2026-23687: CWE-347: Improper Verification of Cryptographic Signature in SAP_SE SAP NetWeaver AS ABAP and ABAP Platform
CVE-2026-23687 is a high-severity vulnerability in SAP NetWeaver AS ABAP and ABAP Platform involving improper verification of cryptographic signatures. An authenticated attacker with normal privileges can obtain a valid signed message and send modified signed XML documents to the verifier. This flaw may lead to acceptance of tampered identity information, unauthorized access to sensitive user data, and disruption of normal system operations.
AI Analysis
Technical Summary
This vulnerability (CWE-347) in SAP NetWeaver AS ABAP and ABAP Platform allows an attacker with normal authenticated privileges to exploit improper verification of cryptographic signatures. By obtaining a valid signed message, the attacker can modify signed XML documents and send them to the system's verifier, potentially causing the system to accept altered identity information. This can result in unauthorized access to sensitive data and disruption of system functionality. The CVSS 3.1 base score is 8.8, reflecting high impact on confidentiality, integrity, and availability. No patch or remediation details are provided in the available data.
Potential Impact
Successful exploitation can lead to acceptance of tampered identity information, unauthorized access to sensitive user data, and potential disruption of normal system usage. The vulnerability affects confidentiality, integrity, and availability of the affected SAP systems.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since no official fix or patch information is provided, organizations should monitor SAP security advisories closely for updates. Until a patch is available, consider restricting access to affected components and applying compensating controls as recommended by SAP.
CVE-2026-23687: CWE-347: Improper Verification of Cryptographic Signature in SAP_SE SAP NetWeaver AS ABAP and ABAP Platform
Description
CVE-2026-23687 is a high-severity vulnerability in SAP NetWeaver AS ABAP and ABAP Platform involving improper verification of cryptographic signatures. An authenticated attacker with normal privileges can obtain a valid signed message and send modified signed XML documents to the verifier. This flaw may lead to acceptance of tampered identity information, unauthorized access to sensitive user data, and disruption of normal system operations.
CVSS v3.1
Score 8.8high
Affected software
SAP_SE
SAP NetWeaver AS ABAP and ABAP Platform
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability (CWE-347) in SAP NetWeaver AS ABAP and ABAP Platform allows an attacker with normal authenticated privileges to exploit improper verification of cryptographic signatures. By obtaining a valid signed message, the attacker can modify signed XML documents and send them to the system's verifier, potentially causing the system to accept altered identity information. This can result in unauthorized access to sensitive data and disruption of system functionality. The CVSS 3.1 base score is 8.8, reflecting high impact on confidentiality, integrity, and availability. No patch or remediation details are provided in the available data.
Potential Impact
Successful exploitation can lead to acceptance of tampered identity information, unauthorized access to sensitive user data, and potential disruption of normal system usage. The vulnerability affects confidentiality, integrity, and availability of the affected SAP systems.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since no official fix or patch information is provided, organizations should monitor SAP security advisories closely for updates. Until a patch is available, consider restricting access to affected components and applying compensating controls as recommended by SAP.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- sap
- Date Reserved
- 2026-01-14T18:26:17.297Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 698aaa0b4b57a58fa1c64d16
Added to database: 02/10/2026, 03:46:19 UTC
Last enriched: 06/16/2026, 08:50:47 UTC
Last updated: 09/10/2026, 22:12:13 UTC
Views: 184
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.