CVE-2026-44748
SAP NetWeaver Application Server ABAP vulnerability analysis and mitigation

Overview

CVE-2026-44748 is a critical XML signature tampering vulnerability (SAML XML Signature Wrapping) in SAP NetWeaver Application Server ABAP and ABAP Platform. It allows an authenticated attacker with normal user privileges to obtain a valid signed message and send modified signed XML documents to the verifier, resulting in acceptance of tampered identity information. The vulnerability affects SAP_BASIS versions 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 758, 816, 918, and 919. It was published on June 9, 2026, as part of SAP's June 2026 Security Patch Day. It carries a CVSS v3.1 base score of 9.9 (Critical) (GitHub Advisory, Feedly).

Technical details

The root cause is classified as CWE-347 (Improper Verification of Cryptographic Signature), specifically an XML Signature Wrapping (XSW) attack pattern (CAPEC-475: Signature Spoofing by Improper Validation). An authenticated attacker intercepts a legitimately signed XML/SAML message, modifies its content (e.g., identity assertions), and resubmits it in a way that the verifier validates the original signature but processes the attacker-controlled payload. The attack requires only low privileges (a standard authenticated account), no user interaction, and is exploitable over the network with low complexity. The changed scope metric indicates that a successful attack can impact resources beyond the vulnerable component itself, such as connected systems trusting the tampered identity assertions (GitHub Advisory, Feedly).

Impact

Successful exploitation enables an attacker to forge identity information accepted by SAP NetWeaver and potentially by downstream systems that trust its SAML assertions, leading to unauthorized access to sensitive user data. The vulnerability has a high impact on confidentiality, integrity, and availability, with a changed scope indicating that connected enterprise systems and integrations may also be compromised. This could facilitate privilege escalation, lateral movement across SAP landscapes, and disruption of normal system operations (GitHub Advisory, Feedly).

Exploitation steps

  1. Reconnaissance: Identify SAP NetWeaver AS ABAP instances running affected SAP_BASIS versions (702–919) accessible over the network. Use tools like Shodan or internal network scanning to locate exposed SAP systems.
  2. Obtain a valid signed XML/SAML message: Authenticate to the SAP system with a low-privileged account and trigger a SAML-based authentication or identity federation flow to capture a legitimately signed XML document (e.g., via a SAML assertion or signed XML message in transit).
  3. Craft a tampered XML document: Using an XML Signature Wrapping (XSW) technique, modify the signed XML document to alter identity-related fields (e.g., username, roles, or group memberships) while preserving the original valid signature in a position the verifier will still accept.
  4. Submit the tampered document: Send the modified signed XML to the SAP NetWeaver verifier endpoint. Due to improper signature verification (CWE-347), the system accepts the tampered identity information as valid.
  5. Achieve unauthorized access: With the forged identity accepted, access sensitive user data, escalate privileges, or propagate the tampered identity to connected systems that trust SAP NetWeaver's assertions (GitHub Advisory, Feedly).

Indicators of compromise

  • Logs: Unexpected SAML assertion validation successes for users with elevated roles or unusual identity attributes; XML signature validation log entries showing mismatches between signed content and processed payload in SAP security audit logs.
  • Network: Unusual or repeated SAML/XML document submissions from a single low-privileged user account; outbound connections from SAP NetWeaver to unexpected external systems following identity assertion processing.
  • Application Behavior: Low-privileged accounts suddenly accessing resources or data normally restricted to higher-privilege users; unexpected session creations or privilege escalations logged in SAP system logs (SM20, SM21).
  • File System: Unexpected configuration changes to SAML trust settings or identity provider configurations on the SAP NetWeaver system.

Mitigation and workarounds

SAP has released a security patch addressing CVE-2026-44748 as part of the June 2026 Security Patch Day; organizations should apply SAP Security Note 3746332 immediately via the SAP Support Portal (SAP Security Note, SAP Patch Day). As interim mitigations, implement network segmentation to restrict which systems can send XML documents to SAP NetWeaver, and monitor for unusual XML signature validation failures and anomalous identity information in system logs. Consider implementing additional message authentication and validation controls at the application level until the patch can be applied (Feedly).

Community reactions

The vulnerability received significant coverage following SAP's June 2026 Patch Day, with multiple security outlets including BleepingComputer, The Hacker News, SecurityWeek, and Heise reporting on the critical flaws patched (BleepingComputer, The Hacker News, SecurityWeek). SAP security specialists Onapsis, SecurityBridge, RedRays, and Layer Seven Security published detailed patch day analyses highlighting CVE-2026-44748 as one of the most critical issues (Onapsis, SecurityBridge). SOCRadar and SecureBulletin specifically called out the CVSS 9.9 SAML bypass as a top priority for remediation (SOCRadar, SecureBulletin). Government CERTs including Belgium's CCB and Singapore's CSA issued advisories urging prompt patching.

Additional resources


SourceThis report was generated using AI

Related SAP NetWeaver Application Server ABAP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-44747CRITICAL9.9
  • SAP NetWeaver Application Server ABAP logoSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
NoYesJul 14, 2026
CVE-2026-44748CRITICAL9.9
  • SAP NetWeaver Application Server ABAP logoSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
NoYesJun 09, 2026
CVE-2026-27671CRITICAL9.8
  • SAP NetWeaver Application Server ABAP logoSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
NoYesJun 09, 2026
CVE-2026-44751HIGH7.1
  • SAP NetWeaver Application Server ABAP logoSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
NoYesJun 09, 2026
CVE-2026-27680MEDIUM4.3
  • SAP NetWeaver Application Server ABAP logoSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
NoNoMay 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management