Back to feed

SAP patches CVSS 10.0 kernel flaw enabling unauthenticated remote code execution

2 min
SAP patches CVSS 10.0 kernel flaw enabling unauthenticated remote code execution

This digest was compiled by AI from multiple sources — links to the originals are below.

SAP released security updates addressing a maximum-severity vulnerability in SAP Extended Passport Processing, tracked as CVE-2026-44756 with a CVSS score of 10.0. The flaw, discovered by Onapsis and codenamed OVERPASS, allows unauthenticated remote attackers to execute arbitrary operating system commands with SAP administrative privileges. SAP also patched a second critical flaw, CVE-2026-58240, a missing authentication check in SAP NetWeaver Message Server.

Key Facts

  • CVE-2026-44756 has a CVSS score of 10.0 and stems from missing boundary validation during deserialization of Extended Passport data.
  • The vulnerability, codenamed OVERPASS, was discovered and reported by SAP security company Onapsis.
  • Exploitation allows attackers to run arbitrary operating system commands on the SAP host with SAP administrative privileges.
  • SAP also patched CVE-2026-58240, a missing authentication check in SAP NetWeaver Message Server with a CVSS score of 9.8.
  • Onapsis assigned the name S4GET to CVE-2026-58240, which affects SAP 9.x kernel lines used by SAP S/4HANA.

OVERPASS Vulnerability

CVE-2026-44756 is a memory corruption flaw in the SAP kernel's processing of the Extended Passport (EPP). The vulnerability is exploitable remotely and without authentication, allowing attackers to run arbitrary operating system commands on the SAP host with SAP administrative privileges. It stems from a missing boundary validation during the deserialization of EPP data, leading to a memory safety violation when processing externally supplied length fields. Onapsis CTO JP Perez-Etchegoyen said a specially-crafted request sent to an affected system can be abused to take control of the receiving process and run operating system commands on the host. Because EPP processing is shared kernel code used by more than one protocol, the flaw is reachable from the internet-facing web layer, the SAP GUI layer, and the RFC layer without credentials.

Exploitation Impact

Successful exploitation can permit an attacker to read the SAP secure store to recover database credentials, password hashes, and all housed business data. Attackers can also read live session data of logged-in users and extract stored credentials to move laterally into every other SAP system. The flaw allows modification of application data, system configuration, and SAP binaries, leading to total compromise of underlying SAP business data and processes.

Second Critical Flaw

SAP also patched CVE-2026-58240, a missing authentication check in SAP NetWeaver Message Server with a CVSS score of 9.8. Onapsis, which also discovered this vulnerability, assigned it the name S4GET. Security researcher Pablo 'Partu' Agustin Artuso described S4GET as a logic flaw, not a misconfiguration, present in SAP's 9.x kernel lines. These kernels are used by SAP S/4HANA and SAP S/4HANA Cloud Private Edition, and potentially other ABAP-based products.

1 source

Time · lag behind first