Critical SAP Kernel Flaw CVE-2026-44756 Allows Pre-Auth Remote Code Execution
A maximum-severity vulnerability dubbed OVERPASS (CVE-2026-44756, CVSS 10.0) has been disclosed in the SAP Kernel, affecting products including SAP NetWeaver AS ABAP, SAP Web Dispatcher, and SAP S/4HANA. The flaw is a buffer overflow in Extended Passport (EPP) processing that can be triggered before any authentication takes place, allowing attackers to execute arbitrary OS commands with SAP administrative privileges. It is exploitable remotely over HTTP(S), SAP GUI, or RFC, requiring no valid SAP account or user interaction. SAP addressed the issue through Security Note 3747649, published on its September 2026 Security Patch Day, and urges organizations to prioritize patching internet-facing systems first. Until patches are applied, SAP recommends restricting access via SAProuter, jump hosts, and Web Dispatcher, while monitoring for application-layer anomalies and suspicious SAP process activity.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.


Discussion (0)
Log in to join the discussion and vote.
Log in