XML External Entity Vulnerability in SAP Integration Suite
CVE-2026-76958
8.5HIGH
What is CVE-2026-76958?
The SAP Integration Suite exhibits a vulnerability where insufficient validation of XML documents from untrusted sources can be exploited. An attacker with low privileges may craft malicious XML payloads containing harmful external entity declarations. The exploitation of this vulnerability could lead to unauthorized access to sensitive file contents on the server, posing significant risks to data confidentiality. Moreover, it may cause resource exhaustion, leading to limited availability. Importantly, this vulnerability does not affect data integrity.
Affected Version(s)
SAP Integration Suite Cloud Integration - Trading Partner Management V2 2.9.2
SAP Integration Suite B2B Integration Factory - Cloud Integration - Trading Partner Management 1.10.0