
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-44751 is a missing authorization vulnerability in SAP Application Server ABAP (NetWeaver and ABAP Platform) that allows authenticated low-privileged users to execute report generation commands and overwrite data belonging to other users, resulting in privilege escalation. It was published on June 9, 2026, and affects SAP_BASIS versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 758, and 816. The vulnerability carries a CVSS v3.1 base score of 7.1 (High) (GitHub Advisory, ENISA EUVD).
The root cause is CWE-862 (Missing Authorization): the ABAP application server fails to perform necessary authorization checks before allowing an authenticated user to execute report generation commands. An attacker with low-privileged network access can invoke these commands over the network without user interaction, causing the server to process the request as if the attacker had broader permissions. This allows the attacker to overwrite report data or output belonging to other users, effectively escalating their privileges within the system. The SAP Security Note 3735546 addresses this flaw (GitHub Advisory, SAP Support).
Successful exploitation results in high integrity impact — an attacker can overwrite information belonging to other users — and low availability impact, with no confidentiality impact. The vulnerability enables privilege escalation within the SAP ABAP environment, potentially allowing a low-privileged user to manipulate business-critical reports or data owned by higher-privileged accounts. Given the broad version range affected (spanning SAP_BASIS 700 through 816), a large number of enterprise SAP deployments could be at risk (GitHub Advisory, Onapsis Blog).
SAP has released a patch via SAP Security Note 3735546, published as part of the June 2026 SAP Security Patch Day. Organizations should apply this note immediately through the SAP Support Portal. As interim mitigations, administrators should review and restrict user authorizations to the minimum necessary, implement proper authorization object checks for report generation transactions, and monitor SAP security audit logs for anomalous report execution activity (SAP Support, SAP Patch Day, Onapsis Blog).
The vulnerability was covered as part of SAP's June 2026 Security Patch Day, which addressed multiple critical flaws across NetWeaver and Commerce Cloud. Security firms including Onapsis, RedRays, SecurityBridge, and SOCRadar published patch day summaries highlighting the broader set of June 2026 SAP vulnerabilities. BleepingComputer reported on the critical flaws fixed in this patch cycle, and CSOOnline noted the patch day as part of a broader trend of high-volume CVE releases (Onapsis Blog, BleepingComputer, SecurityBridge).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."