www.securityweek.com 8 Sept 2026, 14:55 UTC

SAP Fixes Critical EPP Flaw Allowing Full System Compromise

SAP Fixes Critical EPP Flaw Allowing Full System Compromise
CyberSIXT Evidence Panel Source marked as original reporting

SAP has released a patch day containing 20 new and updated security notes, among which a critical memory corruption flaw in Extended Passport (EPP) Processing has been addressed. Tracked as CVE-2026-44756 with a CVSS score of 10/10, the vulnerability stems from missing boundary validations during deserialization of EPP data in the SAP kernel.

Onapsis describes it as allowing unauthenticated, remote attackers to execute arbitrary commands, recover database credentials and password hashes, read live sessions, and modify data, including SAP binaries and configurations. The weakness is triggered when a new user session opens, across multiple protocols, with the EPP processing implemented by default between ABAP systems.

Onapsis notes that the flaw can be reached via web requests, the SAP GUI protocol, and RFC connections, and that the affected components operate under the SAP installation’s OS account, meaning code execution would equate to full system compromise. SAP kernel code spanning S/4HANA, ERP, ECC, NetWeaver, Web Dispatcher, BW/4HANA and related products is implicated. There are no public indicators of active exploitation at this time, and SAP did not report in-the-wild exploitation.

In addition to CVE-2026-44756, the patch day also fixes three other critical flaws: CVE-2026-58240 (missing authentication check in NetWeaver), CVE-2026-76969 (credential disclosure in multitenant CAP deployments), and CVE-2026-66768 (improper access control in NetWeaver).

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline