Executive brief
SAP Manufacturing Integration and Intelligence (MII) is an enterprise application used to integrate and optimize manufacturing operations. A high-privilege attacker can submit malicious input to trigger execution of arbitrary commands on the underlying server, compromising the confidentiality, integrity, and availability of manufacturing data and operations.
Technical details
SAP Manufacturing Integration and Intelligence contains a command injection vulnerability in unspecified functionality that processes user input without sufficient validation. An attacker with high-level privileges can craft malicious input to execute arbitrary operating system commands on the affected system. The vulnerability is network-reachable and requires authentication at an administrative level. Successful exploitation grants the attacker complete control over the affected system, affecting confidentiality, integrity, and availability. SAP released a security patch on August 11, 2026, via the SAP Security Patch Day process (see SAP Note 3758900).
Affected products
- SAP Manufacturing Integration and Intelligence
Timeline
- 2026-08-11: disclosed
- 2026-08-11: patched