Skip to content

CVE-2026-44756

SAP Extended Passport (EPP) memory corruption allows unauthenticated network compromise (CVE-2026-44756)

Critical 10.0 Vendor: SAP Published

SAP Extended Passport (EPP) Processing in SAP kernel and Web Dispatcher lines has a critical memory corruption flaw (CVE-2026-44756). An unauthenticated attacker can send a crafted EPP header to cause undefined behaviour and process termination. Apply SAP Note 3747649.

What happened

SAP describes a memory safety vulnerability in the Extended Passport Protocol (EPP) processing library. An unauthenticated attacker can send a crafted network request containing a malformed EPP header. No user action is required and attack complexity is low, so the flaw is reachable over the network without credentials. The CVSS treats this as scope-changing: the vulnerable component may affect resources beyond its own security boundary.

SAP's description says exploitation may result in undefined behaviour and abnormal program termination, with high impact on confidentiality, integrity and availability. The Common Weakness Enumeration entry is CWE-120. No exploitation or public disclosure is recorded for this CVE.

Who is affected

Affected products are the SAP Extended Passport (EPP) Processing component in KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.53 and 8.04, and WEBDISP 9.16, 9.18 and 9.19. These are SAP kernel and Web Dispatcher lines, so systems running those lines should be considered in scope. If any of these versions are present in your landscape, treat the finding as applicable until you have checked SAP Note 3747649 against your systems.

What to do now

  1. Apply SAP Note 3747649. SAP lists this note as the fix and rates the issue Critical.
  2. Because SAP's advisory gives no workaround, restrict network access to affected SAP kernel and Web Dispatcher systems until the note is applied.
  3. Review your SAP estate for the listed versions, including older kernel lines that may be overlooked outside central production systems.

How to detect it

SAP's September 2026 security note does not list indicators of compromise. Because successful exploitation may cause abnormal program termination, monitor affected kernel and Web Dispatcher components for unexpected crashes or restarts. Investigate such events in the context of network traffic that includes EPP headers, particularly if external exposure to those systems should not have existed.

Beyond the patch

Beyond applying this note, the practical risk is the number of SAP services that accept EPP headers on the network without credentials: if you cannot see them, you cannot patch them. Our SAP security practice can help you locate the affected kernel and Web Dispatcher lines across the estate, and vCISO exposure management can keep network-reachable services in view. Where SAP's patch cadence opens a window, treating that as a supply-chain risk is worth formalising.

Affected and fixed versions

ProductAffectedFixed in
SAP Extended Passport (EPP) ProcessingKRNL64NUC 7.22
7.22EXT
KRNL64UC 7.22
7.53
8.04
WEBDISP 9.16
9.18
9.19
No fixed version listed yet

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them.

Written with AI assistance from the sources above and checked automatically against them before publication.