← Back to CVE List
Vulnerability Intelligence Report
Memory Corruption vulnerability in SAP Extended Passport (EPP) Processing

CVE-2026-44756

A memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing library. Under specific conditions, an unauthenticated attacker could exploit a crafted network request containing a malformed EPP header, potentially resulting in undefined behavior and abnormal program termination. Successful exploitation may have a high impact on the confidentiality, integrity, and availability of the application.

Memory Corruption No Active Exploit Signals
CVSS Base Score
10.0
CRITICAL
Exploitability:3.9
Impact Score:6.1
EPSS Probability:0.32%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-120 ↗CWE-120: Buffer Copy without Checking Size of Input

Affected Products & Versions

Vendor Product Affected Versions
SAP_SE SAP Extended Passport (EPP) Processing KRNL64NUC 7.22 (affected), 7.22EXT (affected), KRNL64UC 7.22 (affected), 7.53 (affected), 8.04 (affected), WEBDISP 9.16 (affected), 9.18 (affected), 9.19 (affected), 9.20 (affected), KERNEL 7.22 (affected), 7.54 (affected), 7.77 (affected), 7.89 (affected), 7.93 (affected), 9.16 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
0.321%
Vulnerability Class
Memory Corruption

Identity & Timeline

StatusPUBLISHED
Assigning AuthoritySAP SE · Vendor · Germany
Reserved2026-05-07T18:31:04
Published2026-09-08T00:10:16
Last Updated2026-09-08T12:42:17

LINK COPIED TO CLIPBOARD