SAP patches maximum severity Overpass flaw in kernel

This digest was compiled by AI from multiple sources — links to the originals are below.
SAP has patched a maximum severity vulnerability in its kernel, tracked as CVE-2026-44756, that could allow unauthenticated attackers to execute arbitrary OS commands on SAP hosts. Security vendor Onapsis discovered the flaw and warned that over 10,000 internet-facing SAP systems may be vulnerable. The vulnerability exists by default in a range of SAP components and is remotely exploitable without authentication.
Key Facts
- CVE-2026-44756 is a memory corruption vulnerability in SAP Extended Passport (EPP) Processing with a maximum CVSS severity rating.
- Onapsis Research Labs discovered the flaw and disclosed it to SAP before publishing details on September 8.
- The vulnerability is remotely exploitable without authentication and exists by default in a range of SAP components.
- Onapsis also urged patching CVE-2026-58240, a critical S/4HANA Message Server flaw with a CVSS score of 9.8.
- Two additional vulnerabilities, CVE-2026-76969 and CVE-2026-66768, have CVSS scores of 9.4 and 9.0 respectively.
The Overpass Flaw
The vulnerability stems from missing boundary validation during deserialization of EPP data, causing a memory safety violation when processing externally supplied length fields. An unauthenticated attacker can send crafted network requests containing a malformed EPP header, leading to undefined behavior and abnormal program termination. Because EPP processing is shared kernel code, the flaw is reachable from the SAP GUI layer used by every end user and from the RFC layer that connects SAP systems to one another. Exploitation could enable remote attackers to run arbitrary OS commands on the SAP host with SAP administrative privileges, allowing full compromise of SAP business data and processes. At the time of Onapsis' disclosure, there was no active exploitation, though the vendor expects this to change.
Additional Critical Patches
Onapsis also urged SAP customers to patch CVE-2026-58240, dubbed S4GET, which affects the Message Server in specific versions of SAP S/4HANA. S4GET carries a CVSS score of 9.8 and could allow an attacker to gain access to the entire SAP system cluster to remotely execute malicious payloads and arbitrary commands. A credential disclosure flaw, CVE-2026-76969, affects multitenant applications using SAP Cloud Application Programming Model and has a CVSS score of 9.4. An improper access control vulnerability, CVE-2026-66768, in SAP NetWeaver has a CVSS score of 9.0 and could enable execution of arbitrary commands on a victim's machine. Onapsis urged SAP customers to take action immediately, especially to patch CVE-2026-44756.