Memory Safety Vulnerability in Extended Passport Protocol by SAP
CVE-2026-44756
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 8 September 2026
Badges
What is CVE-2026-44756?
CVE-2026-44756 is a memory safety vulnerability found within the Extended Passport Protocol (EPP) processing library developed by SAP. This product is primarily employed for facilitating secure transactions and identity management across various applications. The vulnerability arises when an unauthenticated attacker sends a specially crafted network request containing a malformed EPP header. Such a scenario can lead to undefined behavior within the application, which may trigger abnormal program terminations. Organizations utilizing this protocol could face severe repercussions if this vulnerability is exploited, including potential breaches of sensitive data and disruption of critical services.
Potential impact of CVE-2026-44756
-
Compromise of Confidentiality: Successful exploitation may allow attackers to access sensitive information stored within the application or transmitted across the network, leading to data breaches and unauthorized disclosures.
-
Integrity Risks: The vulnerability may enable threat actors to manipulate data or interfere with the application's intended functionality, undermining the integrity of systems relying on the EPP for secure transactions.
-
Availability Issues: Exploitation of this flaw could result in abnormal program terminations, leading to service disruptions or downtime that affect business operations and user access to critical resources.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
SAP Extended Passport (EPP) Processing KRNL64NUC 7.22
SAP Extended Passport (EPP) Processing 7.22EXT
SAP Extended Passport (EPP) Processing KRNL64UC 7.22
News Articles
SAP Patches CVSS 10.0 Kernel Flaw Enabling Unauthenticated Remote Code Execution
SAP patches CVE-2026-44756, an unauthenticated EPP memory corruption flaw that enables remote OS command execution with SAP admin privileges.
12 hours ago
References
CVSS V3.1
Timeline
- π
Vulnerability started trending
- πΎ
Exploit known to exist
- π°
First article discovered by The Hacker News
Vulnerability published
Vulnerability Reserved