Executive brief
SAP Manufacturing Integration and Intelligence contains a missing authorization check vulnerability that allows unauthenticated attackers to send crafted requests to the Cost Servlet and access backend operations without proper authentication. Successful exploitation enables attackers to read, create, modify, or delete sensitive business data, impacting confidentiality, integrity, and availability of the system and potentially exposing critical manufacturing and cost management information.
Technical details
This is an authorization bypass vulnerability (CWE-862: Missing Authorization) in SAP Manufacturing Integration and Intelligence's Cost Servlet component. The vulnerability exists due to insufficient access controls on specific servlet endpoints; attackers can send crafted requests with specific parameter values without authentication to reach backend operations. The attack vector is network-based and requires no authentication or user interaction. Successful exploitation grants unauthorized access to read, create, modify, and delete application-managed business data. The vulnerability was patched as part of SAP Security Patch Day on August 11, 2026 (CVE-2026-44764).
Affected products
- SAP Manufacturing Integration and Intelligence
Timeline
- 2026-08-11: disclosed
- 2026-08-11: patched