CVE-2020-26829 is a critical missing authentication vulnerability in SAP NetWeaver AS JAVA versions 7.11 through 7.50, allowing arbitrary connections to P2P Cluster Communication. This flaw enables unauthenticated attackers to invoke restricted system administration functions, including system shutdown. With a CVSS score of 10.0 (CRITICAL), it presents a severe risk due to its network-based attack vector, low complexity, and complete compromise of confidentiality, integrity, and availability. While not currently in CISA's KEV catalog and lacking public exploit code, it has garnered some community discussion and media coverage, indicating awareness within the security community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.11CPE matchmatch criteria | cpe:2.3:a:sap:netweaver_application_server_java:7.11:*:*:*:*:*:*:* | ||
7.20CPE matchmatch criteria | cpe:2.3:a:sap:netweaver_application_server_java:7.20:*:*:*:*:*:*:* | ||
7.30CPE matchmatch criteria | cpe:2.3:a:sap:netweaver_application_server_java:7.30:*:*:*:*:*:*:* | ||
7.31CPE matchmatch criteria | cpe:2.3:a:sap:netweaver_application_server_java:7.31:*:*:*:*:*:*:* | ||
7.40CPE matchmatch criteria | cpe:2.3:a:sap:netweaver_application_server_java:7.40:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.