ZeroHour

CVE-2026-76971

niche

Authenticated SSRF in SAP Manufacturing Integration and Intelligence (MII)

CVSS 3.1
6.5 medium
EPSS
<1%p4
Published
()
Modified
AI analysis

CVE-2026-76971 is a server-side request forgery (SSRF, CWE-918) vulnerability in SAP Manufacturing Integration and Intelligence (MII) that allows an attacker to make the application server initiate arbitrary outbound requests. The CVSS vector (AV:N/AC:L/PR:L/UI:R/S:C) indicates exploitation requires network access, a low-privileged authenticated session, and user interaction, and if the application processes the attacker-influenced request through its XML/XSL handling, the SSRF can be escalated into script execution. A successful attacker gains low-rated impact on confidentiality, integrity, and availability, consistent with limited script execution within the application's scope rather than full system compromise. Organizations running SAP MII, a specialized manufacturing-integration add-on typically deployed within SAP ERP landscapes at manufacturing sites, are affected; other SAP products patched in the same monthly cycle are not part of this CVE. There is no known public proof of concept, the flaw is not in CISA's KEV catalog, EPSS estimates roughly 0.1% probability of exploitation within 30 days, and no in-the-wild exploitation is known; fixes were released as part of SAP's September 2026 Security Patch Day.

What to do: Apply the SAP Manufacturing Integration and Intelligence update from SAP's September 2026 Security Patch Day, consulting the SAP security note for CVE-2026-76971 for the exact affected and patched versions. Until patching is complete, restrict outbound (egress) network access from MII servers, limit the accounts able to reach the application, and monitor for unexpected outbound connections or XML/XSL processing activity. Because exploitation requires valid low-privileged credentials plus user interaction, also review account provisioning on MII instances.

Affected
SAP Manufacturing Integration and Intelligence (MII)
Estimated exposure
nichelikely on the order of a few hundred to a few thousand installations worldwide — No public install-base or internet-exposed-instance counts exist for SAP MII, a niche manufacturing add-on deployed mainly on internal plant networks at SAP manufacturing customers, so this order-of-magnitude guess is based on the typical…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Due to a Server-Side Request Forgery (SSRF) vulnerability in SAP Manufacturing Integration and Intelligence, an attacker could cause the server to initiate arbitrary outbound requests. If processed by the application, this behavior could be combined with XML/XSL processing to enable execution of scripts. Successful exploitation could result in a low impact on the confidentiality, integrity, and availability of the application.

Weakness
CWE-918
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L

In the news

SAP Security Updates September 2026 – Critical Flaws Patched in SAP NetWeaver, Cloud and Extended Passport

SAP's September 2026 Patch Day fixes 19 notes including CVE-2026-44756 (CVSS 10.0), unauthenticated memory corruption in SAP Extended Passport Processing kernels.

SAP shipped 19 new security notes plus one update across NetWeaver, S/4HANA, Integration Suite, Commerce Cloud, and Cloud Application Programming Model. Top issues include CVE-2026-44756 (CVSS 10.0 memory corruption in SAP Extended Passport Processing across many KERNEL and Web Dispatcher versions), CVE-2026-58240 (CVSS 9.8 missing authentication in NetWeaver Message Server), CVE-2026-76969 (CVSS 9.4 credential disclosure in CAP library sap/cds-mtxs), and CVE-2026-66768 (CVSS 9.0 access control flaw in SAP GUI for Java). No exploitation is reported; organizations running affected kernels are urged to patch urgently.