CVE-2026-44749: SAP SE SAP Gateway

Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.

The SAP Gateway allows attackers to inject content into error messages, potentially leading to disclosure of request artefacts (e.g., regex patterns) and revealing underlying URI parsing logic. Leading to low impact on confidentiality. Integrity and availability are unaffected.

Affected products

  • SAP SE SAP Gateway: version 751 only; version 752 only; version 753 only; version 754 only; version 755 only; version 756 only; …

Published 2026-05-26. Last modified 2026-07-24.