CVE Tools

SAP Patches Critical Extended Passport Processing Vulnerability

SecurityWeekBy Ionut Arghire

PatchSAP KernelOnapsisSAP NetWeaver Message Server

Our summary

SAP has published emergency security updates addressing a critical memory corruption vulnerability, identified as CVE-2026-44756, within its Extended Passport (EPP) processing logic. Security researchers at Onapsis, who dubbed the defect "OVERPASS," warn that unauthenticated attackers can exploit this bug to execute arbitrary system commands, steal database credentials, and manipulate SAP binaries across various platforms including S/4HANA and ERP. The flaw exists because missing boundary validations during data deserialization occur before standard authorization controls are applied, effectively bypassing user locks and role-based restrictions.

Although SAP has not reported active exploitation in the wild, the severity of the issue—rated CVSS 10/10—demands immediate attention from administrators running affected kernel versions. The company also resolved three other high-priority issues, including CVE-2026-58240, which allows unregistered component registration in S/4HANA 2025 and earlier, alongside vulnerabilities affecting NetWeaver and cloud-capable applications.

Read at SecurityWeek

SecurityWeek publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store