
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-44748 is a critical XML signature tampering vulnerability (SAML XML Signature Wrapping) in SAP NetWeaver Application Server ABAP and ABAP Platform. It allows an authenticated attacker with normal user privileges to obtain a valid signed message and send modified signed XML documents to the verifier, resulting in acceptance of tampered identity information. The vulnerability affects SAP_BASIS versions 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 758, 816, 918, and 919. It was published on June 9, 2026, as part of SAP's June 2026 Security Patch Day. It carries a CVSS v3.1 base score of 9.9 (Critical) (GitHub Advisory, Feedly).
The root cause is classified as CWE-347 (Improper Verification of Cryptographic Signature), specifically an XML Signature Wrapping (XSW) attack pattern (CAPEC-475: Signature Spoofing by Improper Validation). An authenticated attacker intercepts a legitimately signed XML/SAML message, modifies its content (e.g., identity assertions), and resubmits it in a way that the verifier validates the original signature but processes the attacker-controlled payload. The attack requires only low privileges (a standard authenticated account), no user interaction, and is exploitable over the network with low complexity. The changed scope metric indicates that a successful attack can impact resources beyond the vulnerable component itself, such as connected systems trusting the tampered identity assertions (GitHub Advisory, Feedly).
Successful exploitation enables an attacker to forge identity information accepted by SAP NetWeaver and potentially by downstream systems that trust its SAML assertions, leading to unauthorized access to sensitive user data. The vulnerability has a high impact on confidentiality, integrity, and availability, with a changed scope indicating that connected enterprise systems and integrations may also be compromised. This could facilitate privilege escalation, lateral movement across SAP landscapes, and disruption of normal system operations (GitHub Advisory, Feedly).
SAP has released a security patch addressing CVE-2026-44748 as part of the June 2026 Security Patch Day; organizations should apply SAP Security Note 3746332 immediately via the SAP Support Portal (SAP Security Note, SAP Patch Day). As interim mitigations, implement network segmentation to restrict which systems can send XML documents to SAP NetWeaver, and monitor for unusual XML signature validation failures and anomalous identity information in system logs. Consider implementing additional message authentication and validation controls at the application level until the patch can be applied (Feedly).
The vulnerability received significant coverage following SAP's June 2026 Patch Day, with multiple security outlets including BleepingComputer, The Hacker News, SecurityWeek, and Heise reporting on the critical flaws patched (BleepingComputer, The Hacker News, SecurityWeek). SAP security specialists Onapsis, SecurityBridge, RedRays, and Layer Seven Security published detailed patch day analyses highlighting CVE-2026-44748 as one of the most critical issues (Onapsis, SecurityBridge). SOCRadar and SecureBulletin specifically called out the CVSS 9.9 SAML bypass as a top priority for remediation (SOCRadar, SecureBulletin). Government CERTs including Belgium's CCB and Singapore's CSA issued advisories urging prompt patching.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."