CVE-2026-44756: Critical SAP Kernel Flaw Enables Unauthenticated Remote Code Execution

CVE-2026-44756: Critical SAP Kernel Flaw Enables Unauthenticated Remote Code Execution

SOC Prime Team
SOC Prime Team linkedin icon Follow

SAP has addressed CVE-2026-44756, a maximum-severity memory corruption vulnerability in Extended Passport (EPP) Processing that could let a remote, unauthenticated attacker execute arbitrary operating system commands on vulnerable SAP systems. The issue, dubbed OVERPASS by Onapsis Research Labs, carries a CVSS score of 10.0 and resides in shared SAP kernel code used by multiple products and communication protocols.

The flaw stems from missing boundary validation while EPP data is deserialized. A specially crafted request containing a malformed EPP header can cause unsafe memory behavior and potentially allow an attacker to take control of the receiving process. Because EPP is processed when a new session opens, exploitation can occur before SAP evaluates user roles, authorization objects, logon policies, or other application-level access controls.

Security teams seeking CVE-2026-44756 detection content can use the SOC Prime Platform to explore behavior-based detection rules and hunting queries mapped to MITRE ATT&CK®. Teams can also use Uncoder AI to convert threat intelligence into detection logic and hunting queries.

Contact Sales

CVE-2026-44756 analysis

Onapsis Research Labs discovered the vulnerability in SAP’s processing of the Extended Passport, a tracing structure attached to requests across the SAP ecosystem. CVE-2026-44756 affects shared kernel functionality used by a broad range of SAP technologies, including S/4HANA, ERP and Business Suite (ECC), NetWeaver, Web Dispatcher, BW/4HANA, Enterprise Portal, PI/PO, Solution Manager, and other products that rely on vulnerable kernel code.

The vulnerability results from insufficient validation of externally supplied length fields during EPP deserialization. An unauthenticated attacker can send a crafted network request with a malformed EPP header, causing a memory safety violation. Successful exploitation can move beyond a crash and allow arbitrary operating system command execution under the account that owns the SAP installation, effectively giving the attacker SAP administrative-level control over the host.

The attack surface is particularly significant because EPP processing is shared across multiple protocols. The flaw can be reached through internet-facing web requests, the SAP GUI protocol used by end users, and Remote Function Call (RFC) connections between SAP systems. EPP is processed as a session is created, before standard SAP authorization checks take effect. As a result, user locks, roles, password policies, Segregation of Duties controls, and transaction restrictions do not block this exploitation path.

A successful attack could expose the SAP secure store, database credentials, password hashes, business information, and live session data. Attackers could also recover stored credentials for lateral movement into other SAP systems and modify application data, system configuration, or SAP binaries. This combination of remote reachability, no authentication requirement, and potential full compromise explains the maximum CVSS 10.0 rating.

Defenders should not rely only on static CVE-2026-44756 IOCs because there is currently no confirmed in-the-wild campaign described by the vendors. Monitoring should instead focus on suspicious requests reaching exposed SAP services, abnormal application-server behavior, unexpected process execution under SAP operating system accounts, and post-exploitation access to credentials or sensitive business data.

CVE-2026-44756 Mitigation

SAP released Security Note 3747649 on September 8, 2026, to address the issue. The patch covers affected ABAP and Java kernels and supported SAP Web Dispatcher versions. SAP lists impacted kernel families and versions in its September 2026 Security Patch Day advisory, and organizations should use the vendor note to determine which systems require updates.

The recommended remediation approach is to inventory the entire SAP landscape and apply the relevant kernel patch immediately, prioritizing internet-facing systems before internal instances. Onapsis emphasizes that a single kernel patch closes the known exploitation vectors. Organizations should also reduce unnecessary external exposure and maintain application-layer monitoring while patches are being rolled out.

No network-only workaround should be considered equivalent to patching. Because the vulnerable EPP functionality is reachable across web, SAP GUI, and RFC communications, blocking one protocol may leave another attack path open. Likewise, strengthening SAP roles or authentication policies does not stop exploitation because the vulnerable code is reached before authentication and authorization controls are evaluated.

To Detect CVE-2026-44756 exploitation attempts, security teams should correlate anomalous activity at SAP-facing services with unusual operating system command execution and changes to sensitive SAP data or binaries. The most authoritative details for CVE-2026-44756 remediation remain SAP Security Note 3747649 and SAP’s September 2026 Security Patch Day guidance.

Disclaimer: Detection content may not be available for every CVE. Check the SOC Prime Platform for current coverage. If you do not find relevant detections now, please check back later.

FAQ

What is CVE-2026-44756 and how does it work?

CVE-2026-44756, also known as OVERPASS, is a critical memory corruption vulnerability in SAP Extended Passport Processing. Missing boundary validation during EPP deserialization allows an unauthenticated remote attacker to send a malformed request that can corrupt memory and potentially execute arbitrary operating system commands with SAP administrative privileges.

When was CVE-2026-44756 first discovered?

Onapsis Research Labs discovered and responsibly disclosed the vulnerability to SAP, but the public sources do not specify the original internal discovery date. The vulnerability was publicly disclosed on September 8, 2026, when SAP released Security Note 3747649 as part of its September Security Patch Day.

What is the impact of CVE-2026-44756 on systems?

Successful exploitation can result in complete compromise of an affected SAP environment. An attacker may execute operating system commands, access database credentials and password hashes, read active user session data, steal credentials for lateral movement, and alter business data, system configurations, or SAP binaries.

Can CVE-2026-44756 still affect me in 2026?

Yes. SAP systems running affected kernel versions remain at risk until the relevant security update is applied. The flaw is remotely exploitable without authentication and is present by default across multiple SAP components, making unpatched internet-facing systems particularly urgent to remediate.

How can I protect myself from CVE-2026-44756

Apply SAP Security Note 3747649 as an emergency priority, starting with internet-facing systems and then patching internal SAP instances. Inventory all SAP components that rely on affected kernel versions, minimize unnecessary external exposure, and monitor application and operating system activity for signs of exploitation during the remediation process.

Join SOC Prime's Detection as Code platform to improve visibility into threats most relevant to your business. To help you get started and drive immediate value, book a meeting now with SOC Prime experts.

More CVEs Articles