CVE-2026-44765
7.3SAP · Manufacturing Integration and Intelligence
A missing authorization check in SAP Manufacturing Integration and Intelligence allows unauthenticated remote attackers to access sensitive scheduling-related functions.
Executive summary
An unauthenticated remote access vulnerability in SAP Manufacturing Integration and Intelligence threatens the security and availability of critical production scheduling functions.
Vulnerability
This is a missing authorization check (CWE-862) that allows an unauthenticated remote attacker to interact with application functions. The vulnerability exists due to a failure to validate user permissions before executing scheduling-related operations.
Business impact
The ability for unauthenticated remote attackers to access scheduling functions can lead to unauthorized modification of manufacturing processes, resulting in operational downtime or data compromise. With a CVSS score of 7.3, this flaw represents a significant risk to industrial control environments and integrated business systems.
Remediation
Immediate Action: Apply the relevant security patches released by SAP through the official security patch day portal to remediate the missing authorization controls.
Proactive Monitoring: Review application access logs for suspicious requests originating from unauthorized network segments or unexpected IP addresses targeting scheduling modules.
Compensating Controls: Implement strict network segmentation and utilize a Web Application Firewall (WAF) to block unauthorized access attempts targeting the vulnerable application endpoints.
Exploitation status
Public Exploit Available: No (exploit_available: unknown)
Analyst recommendation
Organizations utilizing SAP Manufacturing Integration and Intelligence must prioritize this update to prevent unauthorized manipulation of production scheduling. Ensure that security updates are applied immediately following the vendor's guidance to close the authorization gap.