CVE-2026-44764
7.3SAP · Manufacturing Integration and Intelligence
A missing authorization check in SAP Manufacturing Integration and Intelligence allows unauthenticated attackers to send crafted requests to the Cost Servlet.
Executive summary
An unauthenticated authorization bypass vulnerability in SAP Manufacturing Integration and Intelligence exposes the Cost Servlet to unauthorized requests, posing a risk of data manipulation or system impact.
Vulnerability
The application fails to perform necessary authorization checks on the Cost Servlet. This allows an unauthenticated attacker to interact with the servlet directly by sending crafted requests.
Business impact
The CVSS score of 7.3 indicates a high severity risk due to the lack of required authentication for an interface that may handle sensitive manufacturing or financial data. Successful exploitation could lead to unauthorized access to business logic, potential data corruption, or denial of service, which would disrupt manufacturing operations and potentially lead to financial or production reporting inaccuracies.
Remediation
Immediate Action: Update SAP Manufacturing Integration and Intelligence to the latest security patch provided by SAP in note 3758910.
Proactive Monitoring: Review access logs for the Cost Servlet to identify suspicious or unexpected requests originating from unauthorized users.
Compensating Controls: Implement strict network segmentation and utilize a Web Application Firewall (WAF) to filter and block unauthorized requests directed at the affected servlet.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the high CVSS score and the potential for unauthorized interaction with business-critical manufacturing systems, organizations should prioritize the application of the vendor-supplied patch. Administrators must verify their version of SAP XMII and apply the recommended updates immediately to close this authorization gap.