CVE-2026-44758
Received Received - Intake

SAP MII Command Injection Vulnerability

Vulnerability report for CVE-2026-44758, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-11

Last updated on: 2026-08-11

Assigner: SAP SE

Description

SAP Manufacturing Integration and Intelligence (MII) allows an attacker with high privileges to submit specially crafted input to certain affected functionality, which is processed without sufficient validation. Successful exploitation could allow the attacker to execute arbitrary commands on the underlying operating system, resulting in high impact on confidentiality, integrity, and availability of the application.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-11
Last Modified
2026-08-11
Generated
2026-08-11
AI Q&A
2026-08-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
sap manufacturing_integration_and_intelligence *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-94 The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in SAP Manufacturing Integration and Intelligence (MII) allows attackers with high privileges to submit crafted input to certain functions. The input is processed without proper validation, enabling arbitrary command execution on the underlying operating system. This can lead to significant impacts on the application's confidentiality, integrity, and availability.

Impact Analysis

If exploited, this vulnerability could allow attackers to take full control of the affected SAP MII system. This may result in unauthorized access to sensitive data, disruption of manufacturing processes, or complete system compromise, depending on the attacker's goals.

Compliance Impact

This vulnerability could lead to data breaches, violating GDPR and HIPAA requirements for data protection and confidentiality. Organizations may face legal penalties, reputational damage, and loss of compliance certifications if exploited.

Mitigation Strategies

Apply the latest security patches from SAP for SAP MII. Restrict high-privilege user access to only necessary functions. Monitor network traffic for unusual commands or activities. Disable or limit access to affected functionality until patches are applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-44758. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart