Junglewise Threat Intelligence

CVE-2026-76958: SAP Integration Suite XXE vulnerability in XML validation

CVE-2026-76958 · Severity: high · CVSS 8.5 · Published 2026-09-08

Vendors: SAP.

Executive brief

SAP Integration Suite, which handles data integration and API management across enterprise systems, does not properly validate XML documents from untrusted sources. An attacker with low-level credentials could exploit this weakness by submitting specially crafted XML files to read sensitive data from the server, compromising confidentiality, or cause system resource exhaustion affecting availability.

Technical details

This is an XML External Entity (XXE) injection vulnerability in SAP Integration Suite's internal components due to insufficient validation of XML input from untrusted sources. The vulnerability requires low privileges but network access to the affected component. An attacker can submit malicious XML payloads containing external entity declarations to exfiltrate sensitive files (high confidentiality impact) or trigger denial-of-service conditions through entity expansion attacks (low availability impact). The CVSS score of 8.5 reflects the high confidentiality risk and low availability impact with no integrity compromise. Patches are available via SAP Security Patch Day.

Affected products

  • SAP Integration Suite

Timeline

  • 2026-09-08: disclosed

References