SAP Patches Critical Extended Passport Processing Vulnerability
A critical memory corruption vulnerability in the SAP kernel's Extended Passport Processing (EPP) allows unauthenticated remote attackers to execute arbitrary commands, recover secrets, and modify data. The flaw arises from missing boundary validations during deserialization of EPP data, enabling unsafe memory behavior. It affects multiple SAP products relying on the kernel, including S/4HANA, ERP, Business Suite, NetWeaver, and others. Exploitation can occur via web requests, SAP GUI protocol, and RFC connections. The vulnerability is triggered when a new user session opens, bypassing normal authorization controls. SAP has released patches addressing this issue. There are no known exploits in the wild at this time.
AI Analysis
Technical Summary
The vulnerability, tracked as CVE-2026-44756 and dubbed OVERPASS, is a critical memory corruption flaw in SAP's Extended Passport Processing component of the kernel. It results from missing boundary checks during deserialization of externally supplied length fields, causing unsafe memory operations. This flaw allows unauthenticated remote attackers to run arbitrary system commands, recover database credentials and password hashes, read live user sessions, and modify SAP data and binaries. The vulnerability affects numerous SAP products that use the kernel, including S/4HANA, ERP, Business Suite (ECC), NetWeaver, and others. It can be exploited through at least three vectors: web requests, SAP GUI protocol, and Remote Function Call (RFC) connections. Because the vulnerable code runs under the operating system account owning the SAP installation, successful exploitation grants full control over the SAP system. The flaw is triggered as soon as a new user session is opened, before any authorization checks are performed, effectively bypassing all access controls. SAP has released security notes and patches to address this critical issue. No evidence of exploitation in the wild has been reported.
Potential Impact
Successful exploitation allows unauthenticated remote attackers to execute arbitrary commands on the SAP system, recover sensitive secrets such as database credentials and password hashes, read live sessions of logged-in users, and modify critical data including configurations and SAP binaries. This effectively grants attackers full control over the affected SAP system, posing a severe risk to confidentiality, integrity, and availability.
Mitigation Recommendations
SAP has released official security patches addressing this critical vulnerability. Applying these patches promptly is the primary recommended mitigation. There are no indications that the vulnerability has been exploited in the wild. Organizations should review SAP's September 2026 security notes and apply the relevant updates to affected SAP products to remediate the issue.
SAP Patches Critical Extended Passport Processing Vulnerability
Description
A critical memory corruption vulnerability in the SAP kernel's Extended Passport Processing (EPP) allows unauthenticated remote attackers to execute arbitrary commands, recover secrets, and modify data. The flaw arises from missing boundary validations during deserialization of EPP data, enabling unsafe memory behavior. It affects multiple SAP products relying on the kernel, including S/4HANA, ERP, Business Suite, NetWeaver, and others. Exploitation can occur via web requests, SAP GUI protocol, and RFC connections. The vulnerability is triggered when a new user session opens, bypassing normal authorization controls. SAP has released patches addressing this issue. There are no known exploits in the wild at this time.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability, tracked as CVE-2026-44756 and dubbed OVERPASS, is a critical memory corruption flaw in SAP's Extended Passport Processing component of the kernel. It results from missing boundary checks during deserialization of externally supplied length fields, causing unsafe memory operations. This flaw allows unauthenticated remote attackers to run arbitrary system commands, recover database credentials and password hashes, read live user sessions, and modify SAP data and binaries. The vulnerability affects numerous SAP products that use the kernel, including S/4HANA, ERP, Business Suite (ECC), NetWeaver, and others. It can be exploited through at least three vectors: web requests, SAP GUI protocol, and Remote Function Call (RFC) connections. Because the vulnerable code runs under the operating system account owning the SAP installation, successful exploitation grants full control over the SAP system. The flaw is triggered as soon as a new user session is opened, before any authorization checks are performed, effectively bypassing all access controls. SAP has released security notes and patches to address this critical issue. No evidence of exploitation in the wild has been reported.
Potential Impact
Successful exploitation allows unauthenticated remote attackers to execute arbitrary commands on the SAP system, recover sensitive secrets such as database credentials and password hashes, read live sessions of logged-in users, and modify critical data including configurations and SAP binaries. This effectively grants attackers full control over the affected SAP system, posing a severe risk to confidentiality, integrity, and availability.
Mitigation Recommendations
SAP has released official security patches addressing this critical vulnerability. Applying these patches promptly is the primary recommended mitigation. There are no indications that the vulnerability has been exploited in the wild. Organizations should review SAP's September 2026 security notes and apply the relevant updates to affected SAP products to remediate the issue.
Technical Details
- Classification
- {"confidence":0.95,"severitySource":"heuristic","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.securityweek.com/sap-patches-critical-extended-passport-processing-vulnerability/","fetched":true,"fetchedAt":"2026-09-08T15:07:13.336Z","wordCount":1119}
Threat ID: 6aa024a1acd9273b49d16849
Added to database: 09/08/2026, 15:07:13 UTC
Last enriched: 09/08/2026, 15:07:19 UTC
Last updated: 09/09/2026, 02:40:38 UTC
Views: 9
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.