SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-76968

MEDIUM · CVSS 6.5 EPSS 0.23%

Source: NVD + CISA KEV + EPSS · Published 2026-09-08 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Authenticated low-privileged users of SAP Web Dispatcher, Internet Communication Manager, and SAP Content Server can exploit this vulnerability to access administrative functionalities and sensitive system information, leading to potential information disclosure. The risk primarily affects the confidentiality of the application, making it crucial for organizations using these SAP products to prioritize remediation efforts to prevent further exploitation. Security teams should focus on restricting access and monitoring for unusual activities to mitigate the risk.

CVE
CVE-2026-76968
Severity
MEDIUM
CVSS
6.5
EPSS
0.23%

Original NVD Description

SAP Web Dispatcher, Internet Communication Manager and SAP Content Server allows an authenticated low-privileged attacker to access certain administrative functionality or interface and obtain sensitive information about the system state, resulting in information disclosure. This disclosed information could potentially be used to facilitate further attacks. This vulnerability has a high impact on the confidentiality of the application, with no impact on integrity or availability.