CVE-2026-44756: SAP SE SAP Extended Passport Epp Processing
Critical severity, CVSS 10.0. EPSS: 0.7% chance of exploitation in the next 30 days.
A memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing library. Under specific conditions, an unauthenticated attacker could exploit a crafted network request containing a malformed EPP header, potentially resulting in undefined behavior and abnormal program termination. Successful exploitation may have a high impact on the confidentiality, integrity, and availability of the application.
Affected products
- SAP SE SAP Extended Passport Epp Processing: version 7.22EXT only; version 7.53 only; version 8.04 only; version 9.18 only; version 9.19 only; version 9.20 only; …
Published 2026-09-08. Last modified 2026-09-22.