Content Injection Vulnerability in SAP Gateway
CVE-2026-44749

4.3MEDIUM

Key Information:

Vendor

SAP

Vendor
CVE Published:
26 May 2026

What is CVE-2026-44749?

The SAP Gateway has a vulnerability that allows attackers to inject custom content into error messages. This weakness can lead to the disclosure of sensitive request artefacts such as regex patterns, potentially compromising the URI parsing logic. While the confidentiality of the data is at risk due to this injection vulnerability, the integrity and availability of the SAP Gateway remain unaffected.

Affected Version(s)

SAP Gateway SAP_GWFND 750

SAP Gateway 751

SAP Gateway 752

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.