A single, carefully crafted request can slip past SAP’s login check, reach the kernel, and hand an attacker complete command of the server. Consequently, the intruder gains far more than the application itself. They also seize credentials, live sessions, financial records, and a company’s most sensitive business data.
This alarming scenario belongs to a newly disclosed flaw. Security researchers have named it OVERPASS, and its severity is difficult to overstate.
What Is the OVERPASS Vulnerability?
The critical flaw, tracked as CVE-2026-44756, earned the maximum CVSS score of 10.0. Moreover, it resides deep within the SAP Kernel code that handles the Extended Passport Protocol (EPP). SAP relies on EPP to trace requests and follow calls as they travel between connected systems.
Fundamentally, the danger springs from the exact moment EPP is parsed. The kernel dissects the structure the instant a new session opens, which happens before the user is ever authenticated.
Why Traditional Defenses Fail
Because the flawed code runs so early, familiar safeguards simply do not apply. Account lockouts, complex passwords, roles, and authorization limits therefore offer no protection whatsoever.
Instead, a specially formed request lets the attacker hijack the process outright. From there, they can execute arbitrary operating system commands with full SAP administrative privileges.
Multiple Doors Into the Same Weakness
OVERPASS is especially insidious because it exposes several access paths at once. An attacker can reach the vulnerable code through the web layer via SAP Internet Communication Manager and SAP Web Dispatcher. Alternatively, they can arrive through SAP GUI connections or Remote Function Call channels.
Closing a single protocol does help somewhat. However, it merely shrinks the attack surface rather than removing the underlying flaw.
The Devastating Aftermath of a Breach
Once inside, an attacker gains sweeping and destructive control. Specifically, they can read the SAP Secure Store, extract database credentials, and harvest password hashes. Furthermore, they can intercept data from active user sessions and lift saved credentials to pivot across linked SAP systems.
Such access also permits changes to configurations, applications, and the SAP binaries themselves. As a result, analysts warn of grim scenarios. These include the theft of financial and personnel data, the alteration of supplier banking details, the creation of privileged accounts, the planting of backdoors, and the launch of ransomware.
A Sprawling List of Affected Products
Since OVERPASS lives in shared kernel code, the circle of exposed products grows remarkably wide. Affected solutions include SAP S/4HANA, SAP ERP and Business Suite, NetWeaver Application Server ABAP, Web Dispatcher, BW/4HANA, Enterprise Portal, PI/PO, Solution Manager, and other offerings built on the same kernel.
The scale of exposure is equally sobering. Onapsis specialists identified more than 10,000 unique IP addresses presenting internet-facing SAP web interfaces, and they consider that figure conservative.
Is Anyone Exploiting It Yet?
At the time of publication, the Onapsis team had found no signs of OVERPASS being exploited in real attacks. Nevertheless, history counsels caution. Past incidents have shown that attackers can dissect released SAP patches and pivot to exploiting critical bugs within mere days.
Administrators are therefore urged to act deliberately. First, they should verify kernel versions on internet-facing systems. Afterward, they must update internal, test, and forgotten instances as well.
How to Fix the SAP OVERPASS Flaw
SAP closed the vulnerability during its September security update release. The vendor issued Security Note 3747649 in the September patch day, and a single kernel fix seals every known exploitation path for CVE-2026-44756.
According to Onapsis remediation guidance, only a kernel update can eliminate the risk entirely. Network restrictions can temporarily narrow the attack surface, yet they cannot shield every interface at once, because the vulnerable EPP is processed across several protocols before any authorization check occurs.
Speed Has Already Proven Critical
Reaction time for SAP systems became a decisive factor only recently. In August, attackers began striking SAP Commerce Cloud through another CVSS 10.0 flaw just three days after the fix appeared, even before a public exploit existed.
An even starker example unfolded with SAP NetWeaver in 2025. The maximum-severity CVE-2025-31324 raced from stealthy attacks to mass exploitation. Subsequently, ransomware crews joined the campaign, and investigators discovered malicious web shells on compromised servers.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.