VYPR
Medium severity4.3NVD Advisory· Published May 26, 2026· Updated May 26, 2026

CVE-2026-44749

CVE-2026-44749

Description

The SAP Gateway allows attackers to inject content into error messages, potentially leading to disclosure of request artefacts (e.g., regex patterns) and revealing underlying URI parsing logic. Leading to low impact on confidentiality. Integrity and availability are unaffected.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

SAP Gateway error message content injection allows attackers to leak request artifacts such as regex patterns, revealing URI parsing logic with low confidentiality impact.

Vulnerability

The SAP Gateway contains a content injection vulnerability in error message handling. An attacker can inject content into error responses, causing the disclosure of request artifacts such as regex patterns and revealing underlying URI parsing logic. This issue affects SAP Gateway systems as described in SAP Security Notes published on Patch Day [1]. No specific version numbers are provided in the available references.

Exploitation

An attacker requires network access to the SAP Gateway service. No authentication is required. By crafting a request with specially chosen values that trigger error responses, the attacker can inject content that is reflected back in the error message, thereby revealing internal processing details such as regex patterns and URI parsing logic.

Impact

Successful exploitation leads to low impact on confidentiality as defined by the CVSS v3 score of 4.3 (Medium). The attacker gains insight into the Gateway's URI parsing logic and related request artifacts, which could aid in further attacks. Integrity and availability are not affected.

Mitigation

SAP has released security notes addressing this vulnerability as part of its regular SAP Security Patch Day [1]. Customers should apply the relevant SAP Security Notes for their Gateway installations. Affected systems should be updated to the latest support packages that include the fix as per SAP's maintenance strategy for low and medium severity notes [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.