SAP Patches Maximum Severity “Overpass” Flaw
Onapsis warns over 10,000 internet-facing SAP systems may be exposed to maximum-severity unauthenticated RCE flaw CVE-2026-44756 in SAP Extended Passport.
Onapsis Research Labs discovered CVE-2026-44756, a memory corruption flaw in SAP Extended Passport (EPP) processing caused by missing boundary validation during deserialization. The bug is reachable from the SAP GUI and RFC layers, is remotely exploitable without authentication by default, and could let attackers run arbitrary OS commands with SAP administrative privileges. No active exploitation was observed at publication. Onapsis also flagged critical S4GET bug CVE-2026-58240 (CVSS 9.8) in the S/4HANA Message Server, credential disclosure CVE-2026-76969 in SAP CAP, and improper access control CVE-2026-66768 in NetWeaver.
- CVE-2026-44756 lives in shared SAP kernel EPP code, reachable via SAP GUI and RFC
- Unauthenticated attackers could gain SAP admin privileges and run arbitrary OS commands
- S4GET bug CVE-2026-58240 (CVSS 9.8) affects S/4HANA Message Server
- CAP credential disclosure CVE-2026-76969 and NetWeaver access control bug CVE-2026-66768 also patched
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-44756 | Unauthenticated buffer overflow in SAP Kernel Extended Passport (EPP) processing CVE-2026-44756 is a critical (CVSS 10.0) memory-safety flaw — a classic buffer overflow (CWE-120) — in the Extended Passport Protocol (EPP) processing library of SAP Kernel, the core runtime underlying SAP NetWeaver components (SAP's advisories tie the issue to SAP Kernel and the NetWeaver Message Server). An unauthenticated remote attacker can trigger it by sending a crafted network request containing a malformed EPP header to a system that processes EPP traffic. The malformed header causes undefined behavior and abnormal program termination, and SAP's maximum-severity rating plus vendor coverage of the flaw indicate it can enable unauthenticated remote code execution with high impact on confidentiality, integrity, and availability. Any organization running the affected SAP Kernel/NetWeaver components — essentially typical ABAP-stack SAP deployments — is exposed until patched. No public proof-of-concept is known, the flaw is not in CISA KEV, EPSS estimates only a 0.3% chance of exploitation within 30 days (25th percentile), and fixes shipped in SAP's September 2026 Security Patch Day. Do: Apply the SAP Kernel and NetWeaver Message Server fixes released in SAP's September 2026 Security Patch Day (per the 2026-011 advisory covering this flaw), since specific fixed version numbers are not listed in the available data. As interim mitigation, restrict network access to SAP kernel and message-server services to trusted internal networks and identify any SAP instances exposed to the internet. Check SAP's advisory for the exact patch levels applicable to your kernel releases and prioritize externally reachable systems. | 10.0 | <1% |
| mass≈100,000+ SAP systems plausibly affected (EPP/kernel ships with virtually all ABAP-stack NetWeaver deployments; public scans have historically shown tens of… | ||
| CVE-2026-58240 | Unauthenticated Component Registration Flaw in SAP NetWeaver Message Server SAP NetWeaver Message Server does not sufficiently validate the authenticity of internal application server components when they register with the service (CWE-308). An unauthenticated attacker with network access to the affected service can send a crafted registration request to add or impersonate an application server component. Once registered, the attacker can potentially perform unauthorized actions within the SAP application environment, resulting in a high impact on confidentiality, integrity, and availability — reflected in the critical CVSS 9.8 score. Any organization running SAP NetWeaver deployments that rely on the Message Server is affected; the source data does not specify exact affected version ranges. There is no evidence of active exploitation, no public proof-of-concept, and the issue is not in CISA KEV, with EPSS assigning only a ~0.3% 30-day exploitation probability; a fix shipped in SAP's September 2026 Security Patch Day (a release that also patched other critical flaws, including the separately reported 'OVERPASS' SAP Kernel issue). Do: Apply the SAP NetWeaver Message Server fix from the September 2026 SAP Security Patch Day (referenced as advisory 2026-011) as a priority, since the flaw is unauthenticated and network-triggerable; check SAP's portal for the corrected builds applicable to your release, as no specific version numbers were provided in the source data. Until patching, restrict network access to the Message Server (typically TCP 36xx, e.g., 3600) to trusted application server hosts and internal networks, and verify no message server listener is reachable from the internet. Monitor SAP security notes for updates, as no public exploit exists today. | 9.8 | <1% |
| largetens of thousands of SAP NetWeaver installations plausibly affected (Message Server is a standard component of every NetWeaver stack, with a smaller subset… | ||
| CVE-2026-66768 | Trust Level Policy Bypass Enables RCE in SAP GUI for Java SAP GUI for Java (CWE-807) fails to correctly enforce its trust level policy when certain functions are invoked from a connected backend system, meaning the client relies on untrusted backend input when making security decisions. To exploit it, an attacker needs low-privileged access to a connected backend (for example, a compromised or malicious SAP backend) and must manipulate that backend to trigger the affected functionality, which also requires interaction from the logged-in user (CVSS UI:R). Successful exploitation yields arbitrary command execution on the victim's workstation, with the changed-scope vector (S:C) allowing a backend-level foothold to break out onto the end-user machine and seriously impacting its confidentiality, integrity, and availability. Anyone running SAP GUI for Java to connect to SAP backends is exposed, particularly in scenarios where less-trusted or low-privileged users can influence the backend their colleagues connect to. There is no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS estimates only a 0.3% chance of exploitation in the next 30 days, so no in-the-wild exploitation is currently known; a fix shipped as part of SAP's September 2026 security patch day. Do: Deploy the SAP GUI for Java patch released with SAP's September 2026 security updates, checking the SAP advisory for the exact affected and fixed versions for your release line. Inventory endpoints running SAP GUI for Java (especially macOS/Linux desktops) and the backends they connect to, prioritizing users who connect to backends accessible to low-privileged or external users. As an interim mitigation, restrict low-privileged accounts' ability to invoke the affected backend functions and treat backend compromise as a path to client workstation takeover when assessing risk. | 9.0 | <1% |
| large≈ hundreds of thousands of end users/desktops (subset of SAP's multi-million-user ERP client base using the Java edition) | ||
| CVE-2026-76969 | Unauthenticated Credential Theft and Tenant Data Tampering in SAP @sap/cds-mtxs CVE-2026-76969 is a critical flaw (CVSS 9.4) in SAP's @sap/cds-mtxs npm package, the multitenancy component of the SAP Cloud Application Programming Model (CAP), which performs insufficient checks on certain functionality used in multitenant CAP applications with extensibility enabled. An unauthenticated attacker who can reach the affected endpoints can send specially crafted requests that cause the service to disclose sensitive credentials. With those credentials, the attacker can replace or delete tenant data, resulting in high impact to integrity and availability and partial impact to the confidentiality of business data. Only deployments running multitenant CAP applications on @sap/cds-mtxs with extensibility enabled are affected. Exploitation has not been observed: there is no known public proof of concept, the issue is not in CISA KEV, and EPSS estimates only a ~0.3% probability of exploitation within 30 days. Do: Update the @sap/cds-mtxs dependency in all multitenant CAP applications to the fixed version given in SAP's security advisory for CVE-2026-76969 (part of SAP's September 2026 patch batch) and redeploy the affected applications. Audit whether your CAP applications use multitenancy with extensibility enabled and whether the mtxs endpoints are reachable without authentication, and rotate any tenant-scoped credentials that could have been exposed. As an interim mitigation, restrict network access to the mtxs/sidecar endpoints to trusted callers. | 9.4 | <1% |
| nichelikely low thousands to low tens of thousands of multitenant CAP tenant deployments (estimate; exact counts unknown) |
Full article361 words · extracted from infosecurity-magazine.com · click to collapse
Over 10,000 internet-facing SAP systems might be vulnerable to a maximum severity vulnerability in the SAP kernel, security vendor Onapsis has warned.
The firm’s Onapsis Research Labs (ORL) discovered and responsibly disclosed to SAP the Memory Corruption vulnerability in SAP Extended Passport (EPP) Processing, tracked as CVE-2026-44756.
“The ORL team discovered that boundary validation is missing during the deserialization of EPP data resulting in a memory safety violation when processing externally supplied length fields,” it explained in a blog on September 8.
“This allows an unauthenticated attacker to send crafted network requests containing a malformed EPP header, causing undefined behavior and abnormal program termination.”
Read more on SAP vulnerabilities: SAP S/4HANA Users Urged to Patch Critical Exploited Bug.
Onapsis explained that, because EPP processing is shared kernel code the vulnerability is reachable from the SAP GUI layer every end user connects to, and from the RFC layer that links SAP systems to one another.
It warned that the bug is remotely exploitable without authentication and exists by default in a range of SAP components.
Exploitation could enable remote attackers to run arbitrary OS commands on the SAP host with SAP administrative privileges, enabling full compromise of SAP business data and processes.
At the time of writing there was no active exploitation, although this is likely to change.
More CVEs for SAP Customers to Patch
Onapsis also urged SAP customers to patch CVE-2026-58240, another critical bug, this time with a CVSS score of 9.8.
Dubbed “S4GET,” it affects the Message Server in specific versions of SAP S/4HANA and could allow an attacker to gain access to the entire SAP system cluster to remotely execute malicious payloads and arbitrary commands, the firm explained.
Two further vulnerabilities include:
- A credential disclosure flaw (CVE-2026-76969) in multitenant applications using SAP Cloud Application Programming Model (CAP). It has a CVSS score of 9.4 and is patched with Security Note #3798315
- An improper access control vulnerability (CVE-2026-66768) in SAP NetWeaver with a CVSS score of 9.0. It is patched with SAP Security Note #3781729, and could enable execution of arbitrary commands on a victim’s machine
Onapsis urged SAP customers to take action immediately, especially to patch CVE-2026-44756.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/sap-patches-maximum-severity/