
Cloud Vulnerability DB
Eine von der Community geführte Datenbank für Schwachstellen
CVE-2026-44756, dubbed "Overpass", is a critical memory safety vulnerability in SAP's Extended Passport Protocol (EPP) processing library that allows unauthenticated remote attackers to trigger undefined behavior and abnormal program termination via a crafted malformed EPP header. Disclosed on September 8, 2026, as part of SAP's September 2026 Security Patch Day, it affects multiple SAP kernel and web dispatcher versions including KRNL64NUC 7.22, KRNL64UC 7.22/7.53/8.04, KERNEL 7.22/7.54/7.77/7.89/7.93/9.16, and WEBDISP 9.16/9.18/9.19/9.20. The vulnerability carries a maximum CVSS v3.1 base score of 10.0 (Critical) with a changed scope, reflecting its potential to impact components beyond the vulnerable service itself (GitHub Advisory, SAP Note 3747649).
The root cause is classified as CWE-120 (Buffer Copy without Checking Size of Input — Classic Buffer Overflow): the EPP processing library copies an attacker-controlled input buffer without validating its size against the destination buffer, leading to a heap or stack overflow (GitHub Advisory). An unauthenticated attacker can send a specially crafted network request containing a malformed EPP header to any exposed SAP service that processes EPP data (including DIAG, RFC, and HTTP/HTTPS endpoints handled by the SAP kernel or Web Dispatcher), requiring no credentials or user interaction. The overflow triggers undefined behavior that can result in abnormal program termination or, under favorable memory layout conditions, arbitrary code execution; the vulnerability is automatable and exploitable across multiple protocols (Onapsis Blog, Dev.to Write-up).
Successful exploitation can result in high impact to confidentiality, integrity, and availability of the affected SAP application, with a changed scope indicating that components beyond the vulnerable EPP library itself may be affected. An unauthenticated attacker can crash the SAP kernel or Web Dispatcher process (denial of service), potentially disclose sensitive memory contents through undefined behavior, and under optimal conditions achieve unauthenticated remote code execution (RCE) on the underlying host — granting full control of the SAP ERP system (GitHub Advisory, SecurityWeek). With over 10,000 internet-facing SAP systems estimated to be at risk, successful exploitation could enable lateral movement into connected enterprise systems, data exfiltration of business-critical ERP data, and disruption of core business operations (4sysops, BleepingComputer).
As of the time of disclosure, there is no public proof-of-concept exploit and no confirmed in-the-wild exploitation (GitHub Advisory). The NVD SSVC assessment confirms exploitation is currently "none" but notes the vulnerability is automatable with total technical impact, making it a high-priority target for threat actors. The EPSS score is approximately 0.321%, reflecting a relatively low near-term exploitation probability at time of publication, though the maximum CVSS score and zero-authentication requirement significantly elevate risk. No threat actor attribution or CISA KEV catalog listing has been reported at this time (Feedly Intelligence, CIS Advisory).
core.*) in the SAP instance directory; new or modified files in the SAP executable directory created by the SAP service account; web shells or unauthorized scripts in the Web Dispatcher document root.disp+work, gwrd, icman) restarting unexpectedly or spawning unusual child processes (e.g., /bin/sh, cmd.exe); elevated CPU or memory usage in SAP kernel processes without corresponding business activity (Onapsis Blog, RedRays Blog).SAP has released patches via SAP Note 3747649 (September 2026 Security Patch Day); organizations should apply the relevant kernel patches for their affected versions immediately — this covers KRNL64NUC 7.22, KRNL64UC 7.22/7.53/8.04, KERNEL 7.22/7.54/7.77/7.89/7.93/9.16, and WEBDISP 9.16/9.18/9.19/9.20 (SAP Note 3747649, SAP Patch Day). As a network-level workaround prior to patching, restrict access to SAP kernel ports and Web Dispatcher endpoints to trusted IP ranges using firewalls or network ACLs, preventing unauthenticated external access to EPP-processing services. Additionally, deploy memory safety monitoring tools, enable SAP kernel crash alerting, and monitor system logs for abnormal terminations as detection controls while patches are being applied (Onapsis Blog, CIS Advisory).
The vulnerability attracted significant attention from the SAP security community, with Onapsis publishing a dedicated remediation blog and hosting a webinar on the September 2026 patch day vulnerabilities (Onapsis Blog). BleepingComputer, SecurityWeek, The Hacker News, and Infosecurity Magazine all covered the disclosure, highlighting the maximum CVSS 10.0 score and the estimated 10,000+ internet-facing systems at risk (BleepingComputer, The Hacker News). Security researchers on Mastodon and Reddit discussed the vulnerability's severity and the urgency of patching, with CERT-EU issuing a formal security advisory (CERT-EU Advisory). RedRays and Layer Seven Security published technical analyses of the SAP Note and exploitation surface, and SOC Prime released detection content for the vulnerability (RedRays Blog, SOC Prime).
Quelle: Dieser Bericht wurde mithilfe von KI erstellt
Kostenlose Schwachstellenbewertung
Bewerten Sie Ihre Cloud-Sicherheitspraktiken in 9 Sicherheitsbereichen, um Ihr Risikoniveau zu bewerten und Lücken in Ihren Abwehrmaßnahmen zu identifizieren.
Eine personalisierte Demo anfordern
"Die beste Benutzererfahrung, die ich je gesehen habe, bietet vollständige Transparenz für Cloud-Workloads."
"„Wiz bietet eine zentrale Oberfläche, um zu sehen, was in unseren Cloud-Umgebungen vor sich geht.“ "
"„Wir wissen, dass, wenn Wiz etwas als kritisch identifiziert, es auch wirklich kritisch ist.“"