Loading
The Invoker Servlet on SAP NetWeaver Application Server Java platforms, possibly before 7.3, does not require authentication, which allows remote attackers to execute arbitrary code via an HTTP or HTTPS request, as exploited in the wild in 2013 through 2016, aka a "Detour" attack.
Use CWE-306, Sap vendor hub and Netweaver Application Server Java product page to widen CVE-2010-5326 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2023-40309, CVE-2024-22127 and CVE-2024-24743 for nearby disclosures in the same product family. Additional editorial context is available in The Weekly Cybersecurity Brief: February 13th, 2026.