Junglewise Threat Intelligence

CVE-2026-40130: SAP SAPSPrint Service memory corruption in command handling

CVE-2026-40130 · Severity: medium · CVSS 5.3 · Published 2026-08-11

Vendors: SAP.

Executive brief

SAP SAPSPrint Service is a print management component used within SAP systems to handle printing operations. An unauthenticated attacker can send specially crafted requests that trigger a buffer overflow, causing the print service to temporarily stop and automatically restart. While this disrupts printing operations and affects service availability, it does not compromise data confidentiality or integrity.

Technical details

The vulnerability is a memory corruption flaw (buffer overflow) in the SAPSPrint Service's command parsing logic. An unauthenticated attacker with network access can send specially crafted requests to trigger the overflow condition. The affected component does not require authentication, making it directly reachable over the network. Exploitation causes a temporary service crash and automatic restart, resulting in a denial of service against printing functionality but no remote code execution or data breach. A patch is available via SAP Security Patch Day CVE-2026-40130.

Affected products

  • SAP SAPSPrint Service

Timeline

  • 2026-08-11: disclosed
  • 2026-08-11: other: Published on SAP Security Patch Day

References