XML External Entity Vulnerability in SAP Integration Suite
CVE-2026-76958

8.5HIGH

Key Information:

Vendor

SAP

Vendor
CVE Published:
8 September 2026

What is CVE-2026-76958?

The SAP Integration Suite exhibits a vulnerability where insufficient validation of XML documents from untrusted sources can be exploited. An attacker with low privileges may craft malicious XML payloads containing harmful external entity declarations. The exploitation of this vulnerability could lead to unauthorized access to sensitive file contents on the server, posing significant risks to data confidentiality. Moreover, it may cause resource exhaustion, leading to limited availability. Importantly, this vulnerability does not affect data integrity.

Affected Version(s)

SAP Integration Suite Cloud Integration - Trading Partner Management V2 2.9.2

SAP Integration Suite B2B Integration Factory - Cloud Integration - Trading Partner Management 1.10.0

References

CVSS V3.1

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.