SAP has released a set of 20 new and updated security notes, addressing a critical memory corruption vulnerability among other issues. This high-severity flaw, identified as CVE-2026-44756 and scoring the maximum of 10 on the CVSS scale, involves a memory corruption problem within Extended Passport (EPP) Processing.
Understanding the Critical Vulnerability
The vulnerability, termed OVERPASS, arises from the absence of boundary validations during the deserialization of EPP data. This could lead to unsafe memory operations when processing externally supplied length fields, as explained by the application security firm Onapsis. Exploitation of this flaw could allow attackers to execute arbitrary system commands, access sensitive database credentials and password hashes, and manipulate live user sessions and configurations.
The defect is embedded within the SAP kernel code, impacting various SAP components since EPP is used for tracing across multiple SAP applications. The vulnerability is activated when a new user session is initiated, spanning multiple communication protocols. Onapsis notes that SAP’s control mechanisms are evaluated after the vulnerability is exploited, posing significant security risks.
Impact on SAP Systems and Components
The affected components include major SAP products like S/4HANA, ERP, Business Suite (ECC), NetWeaver, and others. The vulnerability can be exploited through multiple vectors, such as web requests, the SAP GUI protocol, and Remote Function Call (RFC) connections. The compromised components operate under the operating system account managing the SAP installation, granting attackers substantial control over the system.
Fortunately, there are no indications so far that the vulnerability has been exploited in real-world scenarios. Neither SAP nor Onapsis reports any in-the-wild exploitation attempts, alleviating some immediate concerns.
Additional Security Concerns and Solutions
In addition to the critical flaw in EPP Processing, SAP’s latest patches address three other critical vulnerabilities. These include a missing authentication check in NetWeaver, identified as CVE-2026-58240, which could permit unauthorized remote access. Another flaw, CVE-2026-76969, involves credential disclosure in multitenant applications using the Cloud Application Programming Model (CAP). Additionally, CVE-2026-66768 addresses improper access control issues in NetWeaver.
SAP’s September 2026 security patch also tackles high-severity vulnerabilities in ABAP Developer Tools, Integration Suite, and other components, ensuring a comprehensive enhancement of SAP’s security framework.
Through these proactive measures, SAP demonstrates its commitment to maintaining robust security across its product suite, reinforcing trust among its users and stakeholders.
