Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4355 articles · 196337 vulns · 36/41 feeds (7d)
← Back to list
7.3
CVE-2026-44764
sap · sap manufacturing integration and intelligence

Missing Authorization Check in SAP Manufacturing Integration and Intelligence

Description

Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence, an unauthenticated attacker could send crafted requests to the Cost Servlet using specific parameter values. If processed by the application, these requests enable access to backend operations. Successful exploitation could allow the attacker to read, create, modify, or delete application-managed business data, resulting in a limited impact on the confidentiality, integrity, and availability of the affected system.

Affected Products

VendorProductVersions
sapsap manufacturing integration and intelligenceXMII 15.4, 15.5

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
sapsap softwarecert_advisory90%

References

  • https://me.sap.com/notes/3758910
  • https://url.sap/sapsecuritypatchday

Related News (3 articles)

Tier B
BSI Advisories12d ago
[NEU] [hoch] SAP Patch Day August 2026: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
VulDB13d ago
CVE-2026-44764 | SAP Manufacturing Integration and Intelligence 15.5/XMII 15.4 Cost Servlet improper authorization
→ No new info (linked only)
Tier B
CERT-FR13d ago
Multiples vulnérabilités dans les produits SAP (11 août 2026)
→ No new info (linked only)
CVSS 3.17.3 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
CISA KEV❌ No
Actively exploited❌ No
CWECWE-862
PublishedAug 11, 2026
Trending Score13
Source articles3
Independent3
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-58231EXPKEV
Improper Authorization in SAP Commerce Cloud (Data Hub Adapter)
Trending: 55
CRITICALCVE-2026-34265
Memory Corruption vulnerability in Application Server ABAP for SAP NetWeaver and ABAP Platform
Trending: 17
CRITICALCVE-2026-44758
Code Injection vulnerability in Manufacturing Integration and Intelligence
Trending: 14
HIGHCVE-2026-44765
Missing Authorization Check in SAP Manufacturing Integration and Intelligence
Trending: 13
HIGHCVE-2026-58243
Privilege Escalation vulnerability in SAP ABAP Developer Tools
Trending: 11

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 11, 2026
Discovered by ZDM
Aug 11, 2026