Junglewise Threat Intelligence

CVE-2026-44754: SAP ODP-RFC missing authorization in Data Replication API

CVE-2026-44754 · Severity: medium · CVSS 6.6 · Published 2026-06-09

Vendors: SAP.

Executive brief

SAP's data replication interface, used for moving large volumes of business data between systems, contains a flaw where it fails to verify if a calling application is an authorized internal SAP tool. This allows third-party or customer-developed applications to access data in ways the system was not designed to handle. An exploit could lead to the unauthorized disclosure of sensitive business information, though it is unlikely to disrupt system operations or allow data modification.

Technical details

A missing authorization vulnerability (CWE-862) exists in the Remote Function Call (RFC) modules of the SAP Operational Data Provisioning Data Replication API (ODP-RFC). The component fails to perform caller identification to ensure that only permitted SAP-internal applications are accessing the interface. An attacker with high-privileged network access can leverage this to use the API in unintended ways, leading to unauthorized data extraction. While the confidentiality impact is high, the vulnerability does not allow for data modification (integrity) and has minimal impact on service availability.

Affected products

  • SAP Operational Data Provisioning Data Replication API (ODP-RFC)

Timeline

  • 2026-06-09: advisory: SAP published security note 3748819 during the June 2026 Patch Day.

References