Junglewise Threat Intelligence

CVE-2026-44756: SAP Extended Passport Protocol memory safety vulnerability

CVE-2026-44756 · Severity: critical · CVSS 10 · Published 2026-09-08

Vendors: SAP.

Executive brief

A memory safety vulnerability in SAP's Extended Passport Protocol (EPP) processing library could allow unauthenticated attackers to crash applications or cause undefined behavior by sending specially crafted network requests. This could disrupt SAP system availability and potentially compromise the confidentiality and integrity of data processed by affected applications.

Technical details

The vulnerability is a memory safety issue in the EPP processing library that arises when handling malformed EPP headers in network requests. An unauthenticated attacker can trigger undefined behavior and abnormal program termination by sending a crafted network request without requiring authentication or prior access. Successful exploitation may result in denial of service, memory corruption, or information disclosure depending on the underlying memory layout and system conditions.

Affected products

  • SAP Extended Passport Protocol Library <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References