CVE-2026-23687Disclosure(sap / sap_basis)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated attacker with normal privileges to obtain a valid signed message and send modified signed XML documents to the verifier. This may result in acceptance of tampered identity information, unauthorized access to sensitive user data and potential disruption of normal system usage.

0.0/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-347

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • sap_basis

Threat summary

  • 8 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 6 signals
  • Disclosure: 5 classified signals
  • General: 3 classified signals
  • Peaked 2d ago at 6 mentions (2026-02-10); latest day: 1
  • 8 total mentions across 3 days

Affected systems

Vendors
Products
sap_basis

18 versions affected across 1 product

Deep dive

Activity timeline8 mentions / 3d
02356Mentions · 2026-02-10: 6Mentions · 2026-02-12: 1Mentions · 2026-02-15: 1Technical Details · 2026-02-10: 5Technical Details · 2026-02-15: 102-1002-1202-15
Signal classification2 categories
Disclosure
562.5%
General
337.5%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-02-106
Disclosure5General1
2026-02-121
General1
2026-02-151
General1
Full discourse8 posts
  • ZoomEye@zoomeye_team
    Disclosure

    🚨 CVE-2026-23687: SAP NetWeaver AS ABAP & ABAP Platform Identity Spoofing Critical Auth Bypass via XML Signature Wrapping (XSW)! By intercepting a valid message and "wrapping" malicious content within its legitimate signature, authenticated attackers can trick the ABAP Platform's verifier to access sensitive data or disrupt system operations. 📖 Full Vulnerability Details & Analysis at DarkEye: 👉 https://www.darkeye.org/vuln/cve/CVE-2026-23687 🔍 Identify Targets via ZoomEye: Filter: vul.cve="CVE-2026-23687" Search Dork: app="SAP NetWeaver Application Server" Exposure: 16k+ instances identified globally. 👉 ZoomEye Search Link: https://www.zoomeye.ai/searchResult?q=YXBwPSJTQVAgTmV0V2VhdmVyIEFwcGxpY2F0aW9uIFNlcnZlciI%3D&utm_source=twitter&utm_medium=social&utm_campaign=cve_ops_20260210 #SAP #Infosec #CyberSecurity #DarkEye #ABAP #BugBounty

    Post summary

    The post discloses a critical authentication bypass in SAP NetWeaver AS ABAP (CVE‑2026‑23687) involving XML Signature Wrapping, but provides no PoC, exploit, or mitigation information.

    010022102.7K
    11.9K followersView on X
  • Dark Web Informer@DarkWebInformer
    Disclosure

    ‼️ XML Signature Wrapping Vulnerability in SAP NetWeaver ABAP Enables Identity Tampering and Unauthorized Access (CVE-2026-23687) https://darkwebinformer.com/xml-signature-wrapping-vulnerability-in-sap-netweaver-abap-allegedly-enables-identity-tampering-and-unauthorized-access-cve-2026-23687/

    Post summary

    The article announces a new XML Signature Wrapping flaw in SAP NetWeaver ABAP that allows identity tampering and unauthorized access, but it contains no evidence of a PoC, exploit, patch, or active exploitation.

    020713.0K
    164.8K followersView on X
  • tpx Security ⠠⠵@tpx_Security
    Disclosure

    Se reportó la vulnerabilidad CVE-2026-23687 que afecta a SAP NetWeaver AS ABAP & ABAP Platform y que posiblemente permitiría eludir mecanismos de autenticación mediante manipulación de mensajes firmados. El impacto se considera potencial y bajo análisis, sin confirmación de explotación activa hasta el momento.

    Post summary

    A new vulnerability (CVE-2026-23687) affecting SAP NetWeaver may allow authentication bypass through signed message manipulation; no active exploitation has been reported.

    01030163
    3.8K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-23687: HIGH] Vulnerability in SAP NetWeaver ABAP allows attackers to manipulate signed XML docs leading to unauthorized access & data breach. #cybersecurity#cve,CVE-2026-23687,#cybersecurity https://cvefind.com/CVE-2026-23687

    Post summary

    The tweet announces a high‑severity vulnerability in SAP NetWeaver ABAP that permits manipulation of signed XML documents, enabling unauthorized access and potential data breach.

    0001077
    583 followersView on X
  • CRAC Learning - Tech@cracbot
    General

    CVE-2026-23687 (CVSS:8.8, HIGH) is Undergoing Analysis. SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated attacker with normal privileges to obtai..https://nvd.nist.gov/vuln/detail/CVE-2026-23687 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post references CVE‑2026‑23687, noting its high CVSS score and that it is under analysis, but it provides no exploitation details, patches, or proof of concept.

    0000035
    171 followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos SAP ❗ CVE-2026-23687 ❗ CVE-2026-0509 ❗ CVE-2026-0488 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-sap-5/ https://t.co/yyxvzExDno

    Post summary

    The post enumerates three SAP product CVEs but provides no technical details, exploit information, or patch guidance, merely linking to a generic informational page.

    00000114
    6.6K followersView on X
  • DarkEye@darkeye_team
    Disclosure

    🚨 Detailed Analysis for CVE-2026-23687 (SAP NetWeaver Auth Bypass) Stop guessing the risk. The technical details are ready. 🔥 $5 Special Trial to celebrate our CVE Feed launch! Get the Analysis & Prioritized Asset List now: 👉 https://www.darkeye.org/vuln/cve/CVE-2026-23687 Critical Auth Bypass via XML Signature Wrapping (XSW)! Attackers can tamper with signed XML documents to spoof identities and access sensitive data. cc: @zoomeye_team (16k+ targets detected 🎯) #AuthBypass #SAP #ABAP #Infosec

    Post summary

    The post announces a newly disclosed SAP NetWeaver authentication bypass (CVE‑2026‑23687), provides technical details of the vulnerability, but does not mention exploitation, patches, or a PoC.

    00000233
    956 followersView on X
  • RedPacket Security@RedPacketSec
    General

    CVE Alert: CVE-2026-23687 - SAP_SE - SAP NetWeaver AS ABAP and ABAP Platform - https://www.redpacketsecurity.com/cve-alert-cve-2026-23687-sap-se-sap-netweaver-as-abap-and-abap-platform/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-23687 #sap-se #sap-netweaver-as-abap-and-abap-platform

    Post summary

    The tweet merely announces a CVE alert and provides a link, offering no additional technical, exploitation, or remediation details.

    00000106
    3.5K followersView on X
CPE platform detail18 entries

18 of 18 entries

PartVendorProductVersionTarget SWTarget HW
Appsapsap_basis700--
Appsapsap_basis701--
Appsapsap_basis702--
Appsapsap_basis731--
Appsapsap_basis740--
Appsapsap_basis750--
Appsapsap_basis751--
Appsapsap_basis752--
Appsapsap_basis753--
Appsapsap_basis754--
Appsapsap_basis755--
Appsapsap_basis756--
Appsapsap_basis757--
Appsapsap_basis758--
Appsapsap_basis804--
Appsapsap_basis916--
Appsapsap_basis917--
Appsapsap_basis918--

Explore more