CVE-2026-44763

7.6

SAP SE · Manufacturing Integration and Intelligence

SAP Manufacturing Integration and Intelligence contains an improper path validation vulnerability allowing privileged attackers to manipulate file operations.

Executive summary

Insufficient file path validation in SAP Manufacturing Integration and Intelligence allows a privileged attacker to perform unauthorized file operations, potentially compromising system integrity.

Vulnerability

The application is vulnerable to improper limitation of a pathname to a restricted directory (CWE-22). A privileged attacker can use specially crafted input to bypass file path validation and access or modify files outside of the intended directory.

Business impact

With a CVSS score of 7.6, this vulnerability represents a significant risk to system integrity and confidentiality. By manipulating file paths, an attacker could read sensitive configuration files, overwrite critical application components, or gain further execution privileges, leading to full system compromise.

Remediation

Immediate Action: Apply the relevant security patches provided by SAP via the official SAP Security Patch Day channels. Consult SAP Note 3759854 for specific patch instructions.

Proactive Monitoring: Review file system access logs for anomalous activity, specifically looking for attempts to traverse directories or access files outside of standard application paths.

Compensating Controls: Ensure the application service account operates with the principle of least privilege, specifically restricting file system write and read permissions to only the directories absolutely necessary for operation.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Organizations using SAP Manufacturing Integration and Intelligence versions 15.4 or 15.5 must treat this as a high-priority update. Administrators should review the referenced SAP security notes and apply the necessary patches immediately to prevent potential unauthorized file system access.

More SAP SE CVEs