Memory Safety Vulnerability in Extended Passport Protocol by SAP
CVE-2026-44756

10CRITICAL

Key Information:

Vendor

SAP

Vendor
CVE Published:
8 September 2026

Badges

πŸ”₯ Trending nowπŸ“ˆ TrendedπŸ“ˆ Score: 1,970πŸ‘Ύ Exploit ExistsπŸ“° News Worthy

What is CVE-2026-44756?

CVE-2026-44756 is a memory safety vulnerability found within the Extended Passport Protocol (EPP) processing library developed by SAP. This product is primarily employed for facilitating secure transactions and identity management across various applications. The vulnerability arises when an unauthenticated attacker sends a specially crafted network request containing a malformed EPP header. Such a scenario can lead to undefined behavior within the application, which may trigger abnormal program terminations. Organizations utilizing this protocol could face severe repercussions if this vulnerability is exploited, including potential breaches of sensitive data and disruption of critical services.

Potential impact of CVE-2026-44756

  1. Compromise of Confidentiality: Successful exploitation may allow attackers to access sensitive information stored within the application or transmitted across the network, leading to data breaches and unauthorized disclosures.

  2. Integrity Risks: The vulnerability may enable threat actors to manipulate data or interfere with the application's intended functionality, undermining the integrity of systems relying on the EPP for secure transactions.

  3. Availability Issues: Exploitation of this flaw could result in abnormal program terminations, leading to service disruptions or downtime that affect business operations and user access to critical resources.

Affected Version(s)

SAP Extended Passport (EPP) Processing KRNL64NUC 7.22

SAP Extended Passport (EPP) Processing 7.22EXT

SAP Extended Passport (EPP) Processing KRNL64UC 7.22

News Articles

SAP Patches CVSS 10.0 Kernel Flaw Enabling Unauthenticated Remote Code Execution

SAP patches CVE-2026-44756, an unauthenticated EPP memory corruption flaw that enables remote OS command execution with SAP admin privileges.

12 hours ago

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • πŸ“ˆ

    Vulnerability started trending

  • πŸ‘Ύ

    Exploit known to exist

  • πŸ“°

    First article discovered by The Hacker News

  • Vulnerability published

  • Vulnerability Reserved

.