SAP Patches Critical Extended Passport Processing Vulnerability

https://www.securityweek.com/wp-content/uploads/2026/09/SAP_vulnerability-patches.jpg

SAP released 20 new and updated security notes on Tuesday, including one that resolves a critical-severity memory corruption vulnerability.

Tracked as CVE-2026-44756 (CVSS score of 10/10), the critical bug is described as a memory corruption issue in Extended Passport (EPP) Processing.

Missing boundary validations during the deserialization of EPP data could trigger unsafe memory behavior during the processing of externally supplied length fields, application security firm Onapsis explains.

Dubbed OVERPASS, the security defect can be exploited by unauthenticated attackers to run arbitrary system commands, recover database credentials and password hashes, read the live sessions of logged-in users, and modify data, including configurations and SAP binaries.

According to Onapsis, the flaw resides in the SAP kernel code and impacts various components, as EPP is used for tracing within multiple SAP applications.

Furthermore, it explains that the vulnerability is triggered as soon as a new user session is opened, from client...

Copyright of this story solely belongs to www.securityweek.com. To see the full text click HERE

Read more