CVE-2026-44756
10.0SAP · SAP Extended Passport (EPP) Processing
An unauthenticated memory safety vulnerability in the Extended Passport Protocol processing library may allow remote code execution or system instability via a malformed network request.
Executive summary
A critical memory safety vulnerability in SAP Extended Passport Processing allows unauthenticated attackers to achieve remote code execution, posing a severe risk to system integrity and availability.
Vulnerability
This is a buffer copy without checking size of input (CWE-120) vulnerability in the EPP library. An unauthenticated attacker can trigger this flaw by sending a crafted network request with a malformed EPP header, leading to memory corruption.
Business impact
The vulnerability carries a CVSS score of 10.0, indicating the highest level of severity. Successful exploitation allows an attacker to bypass authentication entirely to compromise the confidentiality, integrity, and availability of the affected SAP environment, potentially leading to total system takeover or persistent service disruption.
Remediation
Immediate Action: Review the official SAP Security Note 3747649 to identify and apply the specific security updates or configuration changes recommended for your kernel or Web Dispatcher version.
Proactive Monitoring: Monitor network traffic for unusual or malformed EPP headers and inspect system logs for abnormal application termination events that may indicate exploitation attempts.
Compensating Controls: Implement strict network perimeter controls and utilize a Web Application Firewall to filter traffic, specifically blocking requests containing suspicious or non-compliant EPP headers.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the critical CVSS score and the ability for unauthenticated remote exploitation, this vulnerability must be treated as a top priority. Administrators should reference the provided SAP security documentation immediately to apply the necessary patches and ensure that all affected kernel and Web Dispatcher instances are brought to a secure state.
More SAP CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief critical section