Back to overview

CVE-2026-44748

CRITICAL
9.9
CVSS 3.1
Description
SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated attacker with normal privileges to obtain a valid signed message and send modified signed XML documents to the verifier. This may result in acceptance of tampered identity information leading to unauthorized access to sensitive user data and potential disruption of normal system usage. This causes a high impact on confidentiality, integrity and availability of the application.

Metadata

CVE ID
CVE-2026-44748
State
PUBLISHED
Assigner
sap
Reserved
2026-05-07 18:16 UTC
Published
2026-06-09 00:20 UTC
Last updated
2026-06-09 13:03 UTC
Primary CWE
CWE-347
CWE-347: Improper Verification of Cryptographic Signature
Vendor / Product
SAP_SE / SAP NetWeaver AS ABAP and ABAP Platform
Sources
cve.org  ·  NVD

Severity & Metrics

9.9 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
no
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
SAP_SE SAP NetWeaver AS ABAP and ABAP Platform SAP_BASIS 702, SAP_BASIS 731, SAP_BASIS 740, SAP_BASIS 750 …
Weakness (CWE)
CWESourceDescription
CWE-347 cna CWE-347: Improper Verification of Cryptographic Signature
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.9 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Back to overview