CVE-2026-66768
SAP GUI for Java improper access control allows arbitrary command execution (CVE-2026-66768)
SAP GUI for Java (BC-FES-JAV 8.10) does not correctly enforce trust-level policy for functions invoked by a connected backend system, allowing a low-privileged attacker to run arbitrary commands on a victim's machine (CVSS 9). Apply SAP Note 3781729.
What happened
SAP GUI for Java does not correctly enforce trust-level policy for certain functions invoked from a connected backend system. A low-privileged attacker can exploit this by manipulating a connected backend system to trigger affected functionality. If successful, the attacker could execute arbitrary commands on the victim's machine, with high impact to confidentiality, integrity and availability.
The weakness is reachable over the network. The CVSS vector records low attack complexity, low privileges, and that user interaction is required; a successful attack can also affect resources beyond the component's original boundary. No active exploitation is recorded in the CVE listing, and the vulnerability is not listed in CISA KEV.
Who is affected
SAP NetWeaver (SAP GUI for Java) version BC-FES-JAV 8.10 is affected. This concerns installations of the SAP GUI for Java component when connected to a backend system. Organisations should check for this component on workstations or other client systems used to access SAP NetWeaver.
What to do now
- Apply the fix in SAP Note 3781729. No fixed version number is listed; the correction is identified by the note.
- Inventory installations of SAP NetWeaver (SAP GUI for Java) BC-FES-JAV 8.10 and prioritise rollout on systems that connect to SAP backends from less-controlled networks.
- If you cannot apply the note immediately, restrict which backend systems users connect to and monitor for unusual processes. SAP has not published a workaround in its advisory.
How to detect it
No vendor indicators are listed. Because successful exploitation can allow arbitrary command execution on the victim's machine, EDR or endpoint monitoring should look for unexpected processes started by SAP GUI for Java on affected workstations.
Beyond the patch
Beyond applying the note, this is a reminder to keep an inventory of the SAP client components your teams actually run. SAP delivers corrections through notes on its patch day, and a component like SAP GUI for Java can sit on many workstations; the time between note publication and rollout is the exposure window. Spirity's SAP HANA Security & Cloud Migration practice helps keep SAP estates mapped and patched, and Supply Chain Defense & Third-Party Risk helps track vendor patch cycles so these deadlines do not slip.
Affected and fixed versions
| Product | Affected | Fixed in |
|---|---|---|
| SAP NetWeaver (SAP GUI for Java) | BC-FES-JAV 8.10 | No fixed version listed yet |