CVE-2026-44765 PUBLISHED

Missing Authorization Check in SAP Manufacturing Integration and Intelligence

Assigner: sap
Reserved: 07.05.2026 Published: 11.08.2026 Updated: 11.08.2026

Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence, an unauthenticated remote attacker could access scheduling-related application functions without proper authorization validation. Successful exploitation could allow the attacker to retrieve, create, modify, or delete application-managed scheduling data, causing a low impact on confidentiality, integrity, and availability.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
CVSS Score: 7.3

Product Status

Vendor SAP_SE
Product SAP Manufacturing Integration and Intelligence
Versions Default: unaffected
  • Version XMII 15.4 is affected
  • Version 15.5 is affected

References

Problem Types