CVE-2026-44756 PUBLISHED

Memory Corruption vulnerability in SAP Extended Passport (EPP) Processing

Assigner: sap
Reserved: 07.05.2026 Published: 08.09.2026 Updated: 08.09.2026

A memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing library. Under specific conditions, an unauthenticated attacker could exploit a crafted network request containing a malformed EPP header, potentially resulting in undefined behavior and abnormal program termination. Successful exploitation may have a high impact on the confidentiality, integrity, and availability of the application.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVSS Score: 10

Product Status

Vendor SAP_SE
Product SAP Extended Passport (EPP) Processing
Versions Default: unaffected
  • Version KRNL64NUC 7.22 is affected
  • Version 7.22EXT is affected
  • Version KRNL64UC 7.22 is affected
  • Version 7.53 is affected
  • Version 8.04 is affected
  • Version WEBDISP 9.16 is affected
  • Version 9.18 is affected
  • Version 9.19 is affected
  • Version 9.20 is affected
  • Version KERNEL 7.22 is affected
  • Version 7.54 is affected
  • Version 7.77 is affected
  • Version 7.89 is affected
  • Version 7.93 is affected
  • Version 9.16 is affected

References

Problem Types