Remote Code Execution Vulnerability Discovered in SAP Extended Passport (EPP) Processing (CVE‑2026‑44756)
What Happened — A deserialization flaw in SAP’s Extended Passport (EPP) processing (CVE‑2026‑44756) allows an unauthenticated attacker to send crafted RFC or HTTP requests that trigger arbitrary OS‑level command execution with full SAP administrative privileges. The bug exists in multiple SAP kernel releases and is reachable from the GUI, RFC, and web layers. No public exploitation has been reported yet.
Why It Matters for Trust & Control Assurance
- Demonstrates the need for a continuous vulnerability‑management control that tracks, patches, and validates remediation of critical kernel components across all SAP landscapes.
- Highlights the importance of evidence‑driven control mapping: organizations must be able to prove that patch‑deployment, configuration baselines, and monitoring are in place to satisfy audit requirements.
- Aligns with the Verisq capability Control Mapping, which automates collection of remediation evidence and maps it to the Verisq Common Framework (VCF) control objective for secure system configuration.
Who Is Affected – Large and medium enterprises, government agencies, and any organization running SAP ERP/S/4HANA environments that include the listed kernel versions.
Recommended Actions
- Apply SAP’s security patch for CVE‑2026‑44756 immediately (or follow SAP’s mitigation guidance if patching is delayed).
- Verify that all affected kernel versions are identified in your asset inventory and that patch status is recorded as audit evidence.
- Enhance monitoring of EPP‑related logs for anomalous RFC/HTTP traffic and enable alerting on unexpected process launches.
- Conduct a rapid risk assessment to determine potential impact on critical business processes and update your control‑assurance documentation accordingly.
Source: CIS Advisory 2026‑092
Technical Notes – The vulnerability stems from missing boundary validation during deserialization of EPP data (memory‑safety violation). It is classified under ATT&CK T1190 (Exploit Public‑Facing Application) and can be triggered via the SAP GUI, RFC, or Internet Communication Manager. Affected kernel releases include KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT, KRNL64 7.53, 8.04, WEBDISP 9.16‑9.20, and KERNEL 7.22‑9.20.
Source: CIS Advisory 2026‑092