CVE-2026-44763 PUBLISHED

Directory Traversal vulnerability in SAP Manufacturing Integration and Intelligence

Assigner: sap
Reserved: 07.05.2026 Published: 11.08.2026 Updated: 11.08.2026

SAP Manufacturing Integration and Intelligence allows a privileged attacker to exploit insufficient file path validation in certain functions using specially crafted input. Exploitation also requires a legitimate user to subsequently access the attacker-influenced content and depends on conditions outside the attacker�s control. Successful exploitation could allow files to be written outside the intended directory and affect other components, resulting in a high impact on confidentiality, integrity, and availability.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H
CVSS Score: 7.6

Product Status

Vendor SAP_SE
Product SAP Manufacturing Integration and Intelligence
Versions Default: unaffected
  • Version XMII 15.4 is affected
  • Version 15.5 is affected

References

Problem Types