CVE-2026-44756: Pre-Auth RCE in SAP EPP Processing (ICM, Web Dispatcher, disp+work)
nullFaktor disclosed pre-authentication remote code execution in SAP EPP processing, tracked as critical CVE-2026-44756.
nullFaktor published an advisory for CVE-2026-44756, a stack-based buffer overflow in SAP Extended Passport (EPP) processing. The flaw allows pre-authentication remote code execution and is rated Critical under CVSS 4.0. Affected components are ICM, SAP Web Dispatcher, and dialog work processes (disp+work). The disclosure does not state that exploitation has been observed.
- Stack-based buffer overflow in SAP Extended Passport processing
- Pre-authentication remote code execution, impact rated Critical
- Affects ICM, SAP Web Dispatcher, and dialog work processes
- Tracked as CVE-2026-44756; exploitation is not reported
Vulnerabilities mentionedAll →
- CVE-2026-4475610.0<1%Unauthenticated buffer overflow in SAP Kernel Extended Passport (EPP) processingpublished · SAP Kernel (Extended Passport Protocol (EPP) processing library)
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-44756 | Unauthenticated buffer overflow in SAP Kernel Extended Passport (EPP) processing CVE-2026-44756 is a critical (CVSS 10.0) memory-safety flaw — a classic buffer overflow (CWE-120) — in the Extended Passport Protocol (EPP) processing library of SAP Kernel, the core runtime underlying SAP NetWeaver components (SAP's advisories tie the issue to SAP Kernel and the NetWeaver Message Server). An unauthenticated remote attacker can trigger it by sending a crafted network request containing a malformed EPP header to a system that processes EPP traffic. The malformed header causes undefined behavior and abnormal program termination, and SAP's maximum-severity rating plus vendor coverage of the flaw indicate it can enable unauthenticated remote code execution with high impact on confidentiality, integrity, and availability. Any organization running the affected SAP Kernel/NetWeaver components — essentially typical ABAP-stack SAP deployments — is exposed until patched. No public proof-of-concept is known, the flaw is not in CISA KEV, EPSS estimates only a 0.3% chance of exploitation within 30 days (25th percentile), and fixes shipped in SAP's September 2026 Security Patch Day. |
Posted by Raschin Tavakoli via Fulldisclosure on Sep 22 nullFaktor Security Advisory =========================================================== Title: Pre-Authentication Remote Code Execution in SAP Extended Passport (EPP) processing library Affected Components: ICM, SAP Web Dispatcher, dialog work processes Vulnerability: Stack based Buffer Overflow CVE: CVE-2026-44756 Impact: Critical CVSS 4.0 Vector:...
This source does not provide full text. Read it at seclists.org.