CVE-2026-44758 PUBLISHED

Code Injection vulnerability in Manufacturing Integration and Intelligence

Assigner: sap
Reserved: 07.05.2026 Published: 11.08.2026 Updated: 11.08.2026

SAP Manufacturing Integration and Intelligence (MII) allows an attacker with high privileges to submit specially crafted input to certain affected functionality, which is processed without sufficient validation. Successful exploitation could allow the attacker to execute arbitrary commands on the underlying operating system, resulting in high impact on confidentiality, integrity, and availability of the application.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
CVSS Score: 9.1

Product Status

Vendor SAP_SE
Product SAP Manufacturing Integration and Intelligence
Versions Default: unaffected
  • Version XMII 15.4 is affected
  • Version 15.5 is affected

References

Problem Types