Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5005 articles · 188942 vulns · 37/41 feeds (7d)
← Back to list
7.3
CVE-2026-44764
sap · sap manufacturing integration and intelligence

Missing Authorization Check in SAP Manufacturing Integration and Intelligence

Description

Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence, an unauthenticated attacker could send crafted requests to the Cost Servlet using specific parameter values. If processed by the application, these requests enable access to backend operations. Successful exploitation could allow the attacker to read, create, modify, or delete application-managed business data, resulting in a limited impact on the confidentiality, integrity, and availability of the affected system.

Affected Products

VendorProductVersions
sapsap manufacturing integration and intelligenceXMII 15.4, 15.5

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
sapsap softwarecert_advisory90%

References

  • https://me.sap.com/notes/3758910
  • https://url.sap/sapsecuritypatchday

Related News (3 articles)

Tier B
BSI Advisories1d ago
[NEU] [hoch] SAP Patch Day August 2026: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
VulDB1d ago
CVE-2026-44764 | SAP Manufacturing Integration and Intelligence 15.5/XMII 15.4 Cost Servlet improper authorization
→ No new info (linked only)
Tier B
CERT-FR1d ago
Multiples vulnérabilités dans les produits SAP (11 août 2026)
→ No new info (linked only)
CVSS 3.17.3 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
CISA KEV❌ No
Actively exploited❌ No
CWECWE-862
PublishedAug 11, 2026
Trending Score46
Source articles3
Independent3
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-58231
Improper Authorization in SAP Commerce Cloud (Data Hub Adapter)
Trending: 68
CRITICALCVE-2026-34265
Memory Corruption vulnerability in Application Server ABAP for SAP NetWeaver and ABAP Platform
Trending: 60
CRITICALCVE-2026-44758
Code Injection vulnerability in Manufacturing Integration and Intelligence
Trending: 52
HIGHCVE-2026-44765
Missing Authorization Check in SAP Manufacturing Integration and Intelligence
Trending: 46
MEDIUMCVE-2026-40130
Memory Corruption vulnerability in SAPSPrint Service
Trending: 43

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 11, 2026
Discovered by ZDM
Aug 11, 2026