CVE-2020-26818: SAP NetWeaver Application Server Abap
High severity, CVSS 8.8. EPSS: 1.2% chance of exploitation in the next 30 days.
SAP NetWeaver AS ABAP (Web Dynpro), versions - 731, 740, 750, 751, 752, 753, 754, 755, 782, allows an authenticated user to access Web Dynpro components, which reveals sensitive system information that would otherwise be restricted to highly privileged users because of missing authorization, resulting in Information Disclosure.
Affected products
- SAP NetWeaver Application Server Abap: version 731 only; version 740 only; version 750 only; version 751 only; version 752 only; version 753 only; …
Published 2020-11-10. Last modified 2026-06-17.