CVE-2026-44764

7.3

SAP · Manufacturing Integration and Intelligence

A missing authorization check in SAP Manufacturing Integration and Intelligence allows unauthenticated attackers to send crafted requests to the Cost Servlet.

Executive summary

An unauthenticated authorization bypass vulnerability in SAP Manufacturing Integration and Intelligence exposes the Cost Servlet to unauthorized requests, posing a risk of data manipulation or system impact.

Vulnerability

The application fails to perform necessary authorization checks on the Cost Servlet. This allows an unauthenticated attacker to interact with the servlet directly by sending crafted requests.

Business impact

The CVSS score of 7.3 indicates a high severity risk due to the lack of required authentication for an interface that may handle sensitive manufacturing or financial data. Successful exploitation could lead to unauthorized access to business logic, potential data corruption, or denial of service, which would disrupt manufacturing operations and potentially lead to financial or production reporting inaccuracies.

Remediation

Immediate Action: Update SAP Manufacturing Integration and Intelligence to the latest security patch provided by SAP in note 3758910.

Proactive Monitoring: Review access logs for the Cost Servlet to identify suspicious or unexpected requests originating from unauthorized users.

Compensating Controls: Implement strict network segmentation and utilize a Web Application Firewall (WAF) to filter and block unauthorized requests directed at the affected servlet.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the high CVSS score and the potential for unauthorized interaction with business-critical manufacturing systems, organizations should prioritize the application of the vendor-supplied patch. Administrators must verify their version of SAP XMII and apply the recommended updates immediately to close this authorization gap.

More SAP CVEs