Missing Authorization Check in SAP Manufacturing Integration and Intelligence
CVE-2026-44764

7.3HIGH

Key Information:

Vendor

SAP

Vendor
CVE Published:
11 August 2026

What is CVE-2026-44764?

A vulnerability exists in SAP Manufacturing Integration and Intelligence due to inadequate authorization checks. An unauthenticated attacker may exploit this flaw by sending specially crafted requests to the Cost Servlet, which can potentially permit unauthorized access to backend operations. This could enable the attacker to read, modify, or delete vital business data managed by the application, posing risks to the data's confidentiality, integrity, and availability.

Affected Version(s)

SAP Manufacturing Integration and Intelligence XMII 15.4

SAP Manufacturing Integration and Intelligence 15.5

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.