CVE-2026-44747
Awaiting Analysis Awaiting Analysis - Queue

Memory Corruption in SAP NetWeaver Application Server ABAP

Vulnerability report for CVE-2026-44747, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-14

Last updated on: 2026-07-29

Assigner: SAP SE

Description

SAP NetWeaver Application Server ABAP allows an authenticated attacker to leverage logical errors in memory management to cause a memory corruption that could lead to unauthorized data access, modification, or system unavailability. This has high impact on confidentiality, integrity, and availability of the application.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-14
Last Modified
2026-07-29
Generated
2026-08-03
AI Q&A
2026-07-14
EPSS Evaluated
2026-08-02
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
sap netweaver_application_server_abap *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-787 The product writes data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-44747 is a vulnerability in SAP NetWeaver Application Server ABAP. It allows an authenticated attacker to exploit logical errors in memory management, leading to memory corruption. This corruption can result in unauthorized access to data, modification of data, or even system unavailability.

The vulnerability has a high impact on the confidentiality, integrity, and availability of the affected application. The CVSS v3.1 base score is 9.9, indicating a critical severity level. The vector AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H shows that the attack can be executed over a network with low attack complexity, requires low privileges, and does not need user interaction. It also has a scope change, meaning the impact extends beyond the vulnerable component.

Detection Guidance

The provided context does not include specific detection methods or commands for identifying CVE-2026-44747 on a network or system. Detection typically involves checking for the presence of vulnerable SAP NetWeaver Application Server ABAP versions or monitoring for unusual memory corruption patterns, but no technical details or commands are mentioned.

For accurate detection guidance, refer to SAP's official security notes or patch documentation, as they may provide version checks or diagnostic tools.

Impact Analysis

If you are using SAP NetWeaver Application Server ABAP, this vulnerability could have several impacts:

  • Unauthorized data access: An attacker could gain access to sensitive or confidential data stored or processed by the application.
  • Data modification: An attacker could alter or delete critical data, leading to incorrect business processes or financial losses.
  • System unavailability: The vulnerability could be exploited to crash the system or make it unavailable, disrupting business operations and causing downtime.

Given the high CVSS score, the risk of exploitation is significant, and the consequences could be severe for organizations relying on the affected SAP system.

Compliance Impact

This vulnerability can have serious implications for compliance with various standards and regulations:

  • GDPR (General Data Protection Regulation): If the affected SAP system processes personal data of EU citizens, unauthorized access or modification of this data could lead to violations of GDPR. This may result in hefty fines, reputational damage, and legal consequences for failing to protect personal data adequately.
  • HIPAA (Health Insurance Portability and Accountability Act): If the SAP system handles protected health information (PHI), exploitation of this vulnerability could lead to unauthorized access or disclosure of PHI. This would violate HIPAA's privacy and security rules, potentially resulting in penalties and legal action.
  • Other standards: Depending on the industry, other compliance frameworks like PCI DSS (for payment card data), SOX (for financial reporting), or industry-specific regulations may also be impacted if the vulnerability leads to unauthorized data access or system unavailability.

Organizations must address this vulnerability promptly to avoid compliance violations and the associated risks.

Mitigation Strategies
  • Apply the latest SAP security patches or updates provided by SAP for SAP NetWeaver Application Server ABAP. Refer to SAP Security Notes for the specific patch addressing CVE-2026-44747.
  • Restrict network access to the SAP NetWeaver Application Server ABAP to trusted users and systems only, as the vulnerability requires authenticated access.
  • Monitor SAP's official security resources (e.g., SAP Security Notes) for additional mitigation advice or workarounds if a patch is not immediately available.

For detailed steps, consult Resource 1 (SAP Security Notes & News) or Resource 2 (SAP Note 3747367), as they may contain specific instructions for mitigation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-44747. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart