Server-Side Request Forgery in SAP Manufacturing Integration and Intelligence
CVE-2026-76971

6.5MEDIUM

Key Information:

Vendor

SAP

Vendor
CVE Published:
8 September 2026

What is CVE-2026-76971?

A Server-Side Request Forgery vulnerability discovered in SAP Manufacturing Integration and Intelligence allows an attacker to manipulate the server into making arbitrary outbound requests. If the requests are processed by the application, they could exploit XML/XSL processing features to execute unintended scripts. This flaw could potentially impact the application's confidentiality, integrity, and availability, making it essential for users to ensure their systems are protected from potential exploit attempts.

Affected Version(s)

SAP Manufacturing Integration and Intelligence XMII 15.4

SAP Manufacturing Integration and Intelligence 15.5

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.