SAP patches CVSS 10 OVERPASS kernel bug reachable without credentials

SAP patches OVERPASS, a CVSS 10 kernel bug that lets unauthenticated attackers run commands on SAP hosts.

CSBadmin
2 Min Read

Unauthenticated attackers can now run commands on SAP hosts, and the patch for the flaw behind it carries a perfect CVSS score. SAP fixed OVERPASS, tracked as CVE-2026-44756 with a 10.0 rating, a memory corruption bug in how the kernel deserializes Extended Passport data. Onapsis, which found it, says a crafted network request with a malformed header triggers arbitrary OS commands with SAP administrator rights.

The researcher behind the discovery, Onapsis CTO JP Perez-Etchegoyen, stresses the reach: the vulnerable code serves the web layer, the SAP GUI port and the RFC links between systems, and no credential is needed on any of them. Success means the secure store, database credentials, password hashes and live user sessions all become readable, and stored secrets open the door to lateral movement across the SAP estate. Authorization rules and segregation of duties do not help, since the flaw executes before authentication.

A second critical bug, CVE-2026-58240 at CVSS 9.8, skips an authentication check in the SAP NetWeaver Message Server. Onapsis named it S4GET and says it lives in the 9.x kernels under S/4HANA, reachable through the same port every GUI client uses, so firewalls cannot block it without breaking logon. Exploitation yields code execution as sidadm, the OS user running SAP, across the whole cluster.

Two more patches close CVE-2026-76969 (9.4), a credential disclosure flaw in multi-tenant CAP apps, and CVE-2026-66768 (9.0), an access control bug in SAP GUI for Java. Nothing has been exploited so far, but Onapsis wants SAP shops to inventory systems, patch internet-facing instances first and keep an eye on the application layer during rollout.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.