CVE-2026-44763
7.6SAP SE · Manufacturing Integration and Intelligence
SAP Manufacturing Integration and Intelligence contains an improper path validation vulnerability allowing privileged attackers to manipulate file operations.
Executive summary
Insufficient file path validation in SAP Manufacturing Integration and Intelligence allows a privileged attacker to perform unauthorized file operations, potentially compromising system integrity.
Vulnerability
The application is vulnerable to improper limitation of a pathname to a restricted directory (CWE-22). A privileged attacker can use specially crafted input to bypass file path validation and access or modify files outside of the intended directory.
Business impact
With a CVSS score of 7.6, this vulnerability represents a significant risk to system integrity and confidentiality. By manipulating file paths, an attacker could read sensitive configuration files, overwrite critical application components, or gain further execution privileges, leading to full system compromise.
Remediation
Immediate Action: Apply the relevant security patches provided by SAP via the official SAP Security Patch Day channels. Consult SAP Note 3759854 for specific patch instructions.
Proactive Monitoring: Review file system access logs for anomalous activity, specifically looking for attempts to traverse directories or access files outside of standard application paths.
Compensating Controls: Ensure the application service account operates with the principle of least privilege, specifically restricting file system write and read permissions to only the directories absolutely necessary for operation.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Organizations using SAP Manufacturing Integration and Intelligence versions 15.4 or 15.5 must treat this as a high-priority update. Administrators should review the referenced SAP security notes and apply the necessary patches immediately to prevent potential unauthorized file system access.