Executive brief
SAP SAPSPrint Service is a print management component used within SAP systems to handle printing operations. An unauthenticated attacker can send specially crafted requests that trigger a buffer overflow, causing the print service to temporarily stop and automatically restart. While this disrupts printing operations and affects service availability, it does not compromise data confidentiality or integrity.
Technical details
The vulnerability is a memory corruption flaw (buffer overflow) in the SAPSPrint Service's command parsing logic. An unauthenticated attacker with network access can send specially crafted requests to trigger the overflow condition. The affected component does not require authentication, making it directly reachable over the network. Exploitation causes a temporary service crash and automatic restart, resulting in a denial of service against printing functionality but no remote code execution or data breach. A patch is available via SAP Security Patch Day CVE-2026-40130.
Affected products
- SAP SAPSPrint Service
Timeline
- 2026-08-11: disclosed
- 2026-08-11: other: Published on SAP Security Patch Day