started · updated
SAP kernel vulnerability CVE-2026-44756 requires urgent patching
Onapsis Research Labs has identified a critical vulnerability in the SAP kernel, dubbed ‘OVERPASS’ (CVE-2026-44756), which carries a maximum CVSS score of 10.0. The flaw exists in the processing of the Extended Passport (EPP), a standard tracing structure used to track call sequences across distributed system landscapes.
Because the vulnerability resides in the shared kernel code, it affects three primary access vectors: the internet-facing web layer, the SAP-GUI layer used by end users, and the RFC layer used for communication between SAP systems. This allows for remote execution of arbitrary operating system commands with SAP administrator privileges without requiring authentication.
SAP addressed the issue in September via security note 3747649. A single kernel patch is sufficient to cover all known attack vectors. While the vulnerability is widespread across numerous SAP components, Onapsis reported that no active exploitation in the wild was known at the time of disclosure.