Skip Navigation

September 18, 2026 |

Critical extended Passport flaw impacts SAP systems

Loading table of contents...

At a glance:

  • SAP patched a critical vulnerability in a widely used SAP request-tracing feature that researchers report can lead to compromise of affected SAP systems.

  • Depending on the role of the affected server and its permissions, a successful compromise could expose business-critical data, disrupt ERP operations, or provide a path to connected SAP systems and databases.

  • Teams managing SAP environments can focus on identifying affected systems, deploying available updates, and watching closely for unusual activity while remediation efforts are underway.

Threat summary

On September 15, Onapsis Research Labs issued a threat advisory for its SAPMAP Exploitation Toolkit, which includes proof-of-concept exploits for OVERPASS and other SAP vulnerabilities.

The announcement followed SAP's September 8 release of fixes for CVE-2026-44756, also known as OVERPASS, a critical memory corruption vulnerability in SAP Extended Passport (EPP) processing.

EPP is a tracing feature used by SAP applications to track requests as they move between users, systems, and integrated applications, and is processed by the SAP kernel when a connection is established. The vulnerable functionality is present in a range of SAP products, including:

  • SAP S/4HANA

  • SAP ERP Central Component (ECC)

  • SAP NetWeaver

  • SAP Web Dispatcher

  • SAP Enterprise Portal

  • SAP BW/4HANA

  • SAP Process Integration/Process Orchestration (PI/PO)

  • SAP Solution Manager

Assigned a CVSS score of 10.0, CVE-2026-44756 affects SAP kernel code responsible for processing EPP data. SAP describes the issue as a memory corruption vulnerability, while independent research indicates it is caused by a stack-based buffer overflow in the Extended Passport deserialization process.

EPP data is attached to requests when a connection is established and is processed before SAP evaluates authentication and authorization controls. A specially crafted request can cause the SAP kernel to write data beyond its intended memory boundaries, resulting in memory corruption. Researchers demonstrated exploitation capable of compromising the affected SAP process, and Onapsis Research Labs reports that exploitation can lead to operating system command execution on the SAP host.

The vulnerability can be reached through at least three paths:

  • HTTP or HTTPS requests handled by the Internet Communication Manager or Web Dispatcher
  • SAP Graphical User Interface connections handled by the SAP Dispatcher, and
  • Remote Function Call (RFC) connections used between SAP systems and integrations

Exploitation requires network reachability to a vulnerable SAP service. Internet-facing systems are directly exposed to external threat actors, while internally accessible systems can be reached after compromise of a connected network segment.

Analysis

Organizations with internet-facing SAP web applications, portals, APIs, and SAP Web Dispatcher deployments are likely to face the greatest exposure because the vulnerable functionality can be reached directly through web traffic.

Internal-only systems are also at risk if a threat actor gains access to the corporate network through a compromised workstation, virtual private network account, or another internal system. The same vulnerable code is reachable through SAP GUI and RFC connections, making exposure broader than internet-facing systems alone.

SAP systems are attractive targets because they often sit at the center of critical business operations, including finance, payroll, procurement, manufacturing, and supply chain management. Historical vulnerabilities such as RECON, ICMAD, and CVE-2025-31324 have shown that threat actors actively target SAP systems because a successful compromise can provide access to high-value business data and processes.

What happens after initial compromise depends on the role of the affected system. For example, compromising a development server could expose source code, configuration files, or copied production data. Compromising a production ERP server could provide access to financial records, procurement workflows, human resources information, or other business data processed by that system.

Additional impact is environment-dependent. Organizations often store service credentials on SAP servers and use trusted RFC connections to communicate with other SAP systems. If those credentials or trust relationships are available on the compromised host, a threat actor may be able to access connected systems, databases, or integrated applications. The extent of access depends on how the SAP environment is configured and segmented.

Mitigations

Review SAP systems running affected kernel and SAP Web Dispatcher versions and identify systems that have not yet received the update released in SAP Security Note 3747649. This establishes which environments contain the vulnerable Extended Passport processing code and helps prioritize remediation based on exposure and business criticality. Upgrade affected systems to the patched kernel versions to remove the vulnerable code path used to process malicious Extended Passport data.

Identify internet-facing SAP services, including SAP web applications, APIs, portals, and Web Dispatcher deployments. Prioritizing these systems reduces exposure to external threat actors that can directly reach vulnerable SAP services over the internet.

Review access to SAP GUI, RFC, and administrative interfaces. Limiting access to approved users, systems, and network segments reduces the number of systems capable of reaching vulnerable SAP services while remediation is underway.

Monitor SAP application servers, Web Dispatcher instances, and supporting operating systems for unexpected process crashes, service restarts, operating system commands executed by SAP service accounts, and unusual RFC activity. These events may indicate exploitation attempts or post-compromise activity involving the affected SAP process.

Review trusted RFC connections, service accounts, and credentials stored on SAP servers. Understanding which systems and applications trust a compromised SAP host helps incident responders determine potential lateral movement paths and prioritize containment activities if suspicious activity is identified.

Review guidance provided in the SAP Security Note with the documented HTTP-focused mitigations. These measures can reduce exposure through web-based access paths while organizations complete kernel upgrade activities.

ThreatRoundUp_SignUp_Simplifiedx2

Stay on top of emerging threats like this.

Sign up to receive a weekly roundup of our security intelligence feed. You'll be the first to know of emerging attack vectors, threats, and vulnerabilities. 

Sign up