Skip to main content
CybersecurityVulnerability Management

SAP Patches Maximum Severity Flaw in Kernel Software

Rack-mounted computer equipment in a brightly-lit server room with a blank screen.

"The ORL team discovered that boundary validation is missing during the deserialization of EPP data resulting in a memory safety violation when processing externally supplied length fields," Onapsis Research Labs wrote on September 8.

CVE-2026-44756: a maximum-severity memory corruption in SAP Extended Passport Processing

Security vendor Onapsis reported a Memory Corruption vulnerability in SAP Extended Passport (EPP) Processing, tracked as CVE-2026-44756, and described it as a maximum-severity issue affecting the SAP kernel. Onapsis’ blog dated September 8 said the flaw stems from missing boundary validation during deserialization of EPP data, which creates a memory-safety violation when externally supplied length fields are processed. The firm warned that crafted network requests containing a malformed EPP header can trigger undefined behavior and abnormal program termination.

Scope and reachability: SAP GUI and RFC layers

Onapsis emphasized the kernel-level reach of the vulnerability: EPP processing is shared kernel code. That means the bug is reachable from the SAP GUI layer used by end users and from the RFC layer used to link SAP systems to one another. The vendor said the flaw is remotely exploitable without authentication and exists by default across a range of SAP components, increasing the potential attack surface.

Potential impact: administrative privileges and full compromise

Onapsis warned that exploitation could allow remote attackers to run arbitrary operating-system commands on the SAP host with SAP administrative privileges. The company framed the stakes plainly: successful exploitation could enable full compromise of SAP business data and processes. At the time Onapsis published its findings there was no evidence of active exploitation, though the report stated that this situation is likely to change.

Additional critical SAP vulnerabilities named by Onapsis

Alongside CVE-2026-44756, Onapsis urged SAP customers to address several other high-severity flaws:

  • CVE-2026-58240 — nicknamed "S4GET" by the vendor — affects the Message Server in specific versions of SAP S/4HANA. Onapsis assigned it a CVSS score of 9.8 and said it could allow an attacker to gain access to an entire SAP system cluster to remotely execute malicious payloads and arbitrary commands.
  • CVE-2026-76969 — a credential disclosure flaw in multitenant applications using the SAP Cloud Application Programming Model (CAP). It carries a CVSS score of 9.4 and is patched with SAP Security Note #3798315, according to Onapsis.
  • CVE-2026-66768 — an improper access control vulnerability in SAP NetWeaver with a CVSS score of 9.0, patched with SAP Security Note #3781729; Onapsis said it could enable execution of arbitrary commands on a victim’s machine.

What this means for SAP administrators, enterprise security teams, and auditors

  • SAP administrators: prioritize patching CVE-2026-44756 as the immediate action Onapsis recommended, and verify application of the SAP Security Notes referenced for the other defects. The vendor’s assessment that the EPP flaw is reachable via GUI and RFC layers means administrators should consider both end-user and inter-system interfaces when deploying fixes.
  • Enterprise security teams: treat S4GET (CVE-2026-58240) alongside CVE-2026-44756 as high-priority — Onapsis signaled the potential for cluster-wide compromise in S/4HANA Message Server environments and urged immediate remediation. Teams should inventory internet-facing SAP instances, especially given Onapsis’ estimate that over 10,000 internet-facing SAP systems might be vulnerable.
  • Auditors and compliance officers: document patching and mitigation steps against CVE-2026-44756, CVE-2026-58240, CVE-2026-76969, and CVE-2026-66768, and confirm that the referenced SAP Security Notes (#3798315 and #3781729) have been applied where relevant.

Onapsis said it responsibly disclosed CVE-2026-44756 to SAP and reiterated the urgency of rapid patching. With more than 10,000 internet-facing SAP systems potentially exposed and the vulnerabilities described as remotely exploitable without authentication, the company’s recommendation was explicit: take action immediately, with CVE-2026-44756 singled out for priority attention.

At the time of the Onapsis advisory there was no recorded active exploitation, but the vendor warned that this could change — a reminder that public disclosure accelerates both defensive and offensive activity. For organizations running SAP components, the near-term course is clear in the vendor's own words: apply the available patches and security notes without delay.

Read the original advisory: https://www.infosecurity-magazine.com/news/sap-patches-maximum-severity/