SAP patches critical ‘OVERPASS’ Extended Passport bug
SAP issued 20 security notes fixing CVE-2026-44756 (OVERPASS), a kernel memory-corruption flaw in Extended Passport Processing that can allow unauthenticated command execution and credential access.
SAP released 20 updated security notes on Tuesday addressing a critical memory corruption vulnerability in Extended Passport Processing (CVE-2026-44756), tracked as OVERPASS. The flaw carries a CVSS score of 10.0 and affects SAP kernel code used by multiple core products.
Application security firm Onapsis reported that the defect stems from missing boundary checks during deserialization of EPP data. External length fields can be processed without proper validation, which may trigger unsafe memory behavior when a session is opened. Because EPP handling runs early in session setup, many authentication and authorization checks occur after the vulnerable code executes.
Onapsis noted the issue can be reached via several vectors, including web requests, the SAP GUI protocol and Remote Function Call (RFC) connections. The firm added that the vulnerable functionality is enabled by default between ABAP systems. “Because EPP is processed as the session opens, every SAP control that decides who may do what, including user locks, roles, authorization objects, and logon policies, is evaluated later than the point where the flaw is reached. None of them is in the attacker’s way,” Onapsis wrote.
Products that rely on the affected kernel code include S/4HANA, ERP, Business Suite (ECC), NetWeaver, Web Dispatcher, BW/4HANA, Enterprise Portal, PI/PO and Solution Manager. Onapsis warned that exploitation can enable arbitrary command execution, disclosure of database credentials and password hashes, reading of live user sessions and unauthorized modification of data and SAP binaries. The firm reported no indicators of active exploitation in the wild, and SAP’s security notes do not list known in-the-wild attacks.
SAP’s updates also address three other critical issues. CVE-2026-58240, tracked as S4GET, is a missing authentication check in NetWeaver that Onapsis said affects every S/4HANA 2025 and earlier release. CVE-2026-76969 concerns credential disclosure in multitenant applications using the Cloud Application Programming Model (CAP). CVE-2026-66768 is an improper access control issue in NetWeaver. Five additional security notes published for September 2026 cover high-severity flaws in ABAP Developer Tools, Integration Suite, NetWeaver Business Client, NetWeaver and Commerce Cloud Search and Navigation.
SAP issued the notes and related patches as part of its regular patch cycle. “The affected components run under the operating system account that owns the SAP installation, so code execution under it is equivalent to owning the SAP system outright,” Onapsis wrote. SAP recommends administrators review the security notes and apply the available fixes to affected systems.








