SAP has rolled out essential security updates to mitigate several vulnerabilities, notably an extremely severe flaw in SAP Extended Passport (EPP) Processing. This flaw, identified as CVE-2026-44756, could drastically affect the application’s confidentiality, integrity, and availability.
Understanding CVE-2026-44756
Tracked under CVE-2026-44756, this vulnerability has been rated with a CVSS score of 10.0, indicating its critical nature. The flaw, termed OVERPASS, involves memory corruption in the SAP kernel’s handling of EPP. Discovered by Onapsis, it allows remote, unauthenticated attackers to execute arbitrary OS commands on the SAP host, potentially compromising business data and processes.
The vulnerability arises from inadequate boundary checks during the deserialization of EPP data, leading to potential memory safety issues. Attackers can exploit this by sending crafted network requests with malformed EPP headers, causing unintended behavior and program crashes.
Broader Implications and Exploitation Risks
According to JP Perez-Etchegoyen, CTO of Onapsis, the flaw is embedded in shared kernel code, making it accessible from various interfaces such as internet-facing web layers and SAP GUI layers. Its impact is substantial, as it can be accessed without credentials, posing a significant security challenge.
Exploitation enables attackers to retrieve sensitive information like database credentials and password hashes, access live user session data, and modify application configurations and binaries. It underscores the urgency of addressing this flaw promptly to safeguard SAP systems.
Additional Vulnerabilities and Recommendations
Another critical vulnerability patched by SAP is CVE-2026-58240, known as S4GET, which involves a missing authentication check in SAP NetWeaver Message Server. This flaw allows unauthorized actions by attackers with network access, posing a high risk across SAP S/4HANA and related products.
Further vulnerabilities include CVE-2026-76969 and CVE-2026-66768, involving credential disclosure and improper access control, respectively. Although these have not been exploited yet, the criticality necessitates immediate action.
Onapsis advises users to inventory SAP systems, prioritize patching for internet-facing systems, and monitor for exploitation attempts. Visibility into the SAP application layer is crucial to detect and respond to threats effectively.
In conclusion, while SAP’s recent updates address serious vulnerabilities, vigilance and proactive measures remain essential to protect enterprise systems from potential cyber threats.
