VYPR
Critical severity9.9NVD Advisory· Published Jun 9, 2026· Updated Jun 9, 2026

CVE-2026-44748

CVE-2026-44748

Description

SAP NetWeaver allows authenticated users to tamper with signed XML documents, leading to unauthorized access and system disruption.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

SAP NetWeaver allows authenticated users to tamper with signed XML documents, leading to unauthorized access and system disruption.

Vulnerability

SAP NetWeaver Application Server ABAP and ABAP Platform are vulnerable to a flaw that allows an authenticated attacker with normal privileges to obtain a valid signed message and subsequently send modified signed XML documents to the verifier. This vulnerability affects versions of SAP NetWeaver Application Server ABAP and ABAP Platform that have not yet received the relevant security patch [1].

Exploitation

An attacker must first possess normal user privileges within the affected SAP system. They need to obtain a valid signed message and then craft a modified signed XML document. This tampered document is then sent to the verifier component of the system, exploiting the trust placed in signed messages.

Impact

Successful exploitation allows an attacker to have modified identity information accepted by the system. This can lead to unauthorized access to sensitive user data and can cause disruption to normal system operations, impacting the confidentiality, integrity, and availability of the application.

Mitigation

SAP releases security corrections on a regular SAP Security Patch Day, typically the second Tuesday of every month [1]. Customers are advised to implement these corrections, provided as SAP Security Notes, with high priority. Specific details on the fixed version and release date for this particular vulnerability are not yet disclosed in the available references, but it is recommended to check SAP for Me for the latest SAP Security Notes.

AI Insight generated on Jun 9, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

2

News mentions

1