Through services such as the SAP Security Assessment, Inprosec helps its clients improve the security levels of their SAP systems.
August 2026 Notes
Monthly Summary and Highlights
This month the total number was 31 notes (28 new, 1 security notice and 2 updates), 11 more than in July. This month 4 Hot News were published, the same amount as in the previous period. Regarding high-criticality notes, there are 8, two more than in July. Medium and low notes will not be reviewed, so we will provide detail on a total of 12 notes (all those with a CVSS of 7 or higher).
We have a total of 31 notes for the whole month (28 new, 1 security notice and 2 updates to notes from previous months).
We will review in detail a total of 12 notes, all of high criticality and Hot News:
-
The highest-criticality note of the month (CVSS 10.0) is a Hot News related to “Improper Authorization in SAP Commerce Cloud (Data Hub Adapter)”.
-
The second note in criticality (CVSS 9.9) is another Hot News related to “Code Injection vulnerability in SAP Manufacturing Integration and Intelligence”.
-
The third note in criticality (CVSS 9.8) is another Hot News related to “Memory Corruption vulnerability in Application Server ABAP for SAP NetWeaver and ABAP Platform”.
-
The fourth note in criticality (CVSS 9.1) is another Hot News related to “Code Injection vulnerability in Manufacturing Integration and Intelligence”.
-
The sixth note we will review (CVSS 8.8) is of high criticality and concerns “Privilege Escalation vulnerability in SAP ABAP Developer Tools”.
-
The seventh note we will review (CVSS 8.1) is of high criticality and concerns “Potential buffer overflow vulnerability affects SAP Commerce Cloud in public‑cloud deployments with NGINX”.
-
The eighth note we will review (CVSS 7.9) is of high criticality and concerns “Credentials disclosure in SAP BusinessObjects Business Intelligence Platform (Central Management Server)”.
-
The eighth note we will review (CVSS 7.6) is of high criticality and concerns “Remote Code Execution vulnerability in Enhanced Change and Transport System (CTS+) Attach Tool (ctsattach)”.
-
The ninth note we will review (CVSS 7.6) is of high criticality and concerns “Directory Traversal vulnerability in SAP Manufacturing Integration and Intelligence”.
-
The tenth note we will review (CVSS 7.3) is of high criticality and concerns “Missing Authorization Check in SAP Manufacturing Integration and Intelligence”.
-
The eleventh note with the same criticality (CVSS 7.3) is of high criticality and concerns “Missing Authorization Check in SAP Manufacturing Integration and Intelligence”.
-
The twelfth and last note we will review (CVSS 7.0) is of high criticality and concerns “Multiple vulnerabilities in SAP Business AI Platform (Approuter)”.
This month the most predominant type was “Missing Authorization Check” (8/31 on patch day).
In the chart we can see the classification of August’s notes, as well as the evolution and classification of the previous 5 months (only Sec. Tuesday / Patch Day – by SAP notes)
Full details
The full details of the most relevant notes are as follows (in English):
-
Improper Authorization in SAP Commerce Cloud (Data Hub Adapter) (3771065): SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation. Successful exploitation could enable arbitrary code execution and compromise internal components, resulting in high impact on confidentiality, integrity, and availability of the application. A temporary workaround is available. CVSS v3 Base Score 10,0/10 [CVE-2026-58231]
-
Code Injection vulnerability in SAP Manufacturing Integration and Intelligence (3765948): SAP Manufacturing Integration and Intelligence allows a low-privileged attacker to submit specially crafted input that causes the application to retrieve and process attacker-controlled content from an external source. Successful exploitation could enable execution of arbitrary commands on the underlying host and impact resources beyond the vulnerable component, resulting in high impact on confidentiality, integrity and availability. CVSS v3 Base Score 9,9/10 [CVE-2026-44772]
-
Memory Corruption vulnerability in Application Server ABAP for SAP NetWeaver and ABAP Platform (3714806): SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to exploit logical errors in DIAG protocol parsing, resulting in memory corruption. This vulnerability could disclose confidential system information or crash the system, potentially having a high impact on the confidentiality, integrity, and availability of the application. CVSS v3 Base Score 9,8/10 [CVE-2026-34265]
-
Code Injection vulnerability in Manufacturing Integration and Intelligence (3758900): SAP Manufacturing Integration and Intelligence (MII) allows an attacker with high privileges to submit specially crafted input to certain affected functionality, which is processed without sufficient validation. Successful exploitation could allow the attacker to execute arbitrary commands on the underlying operating system, resulting in high impact on confidentiality, integrity, and availability of the application. A temporary workaround is available. CVSS v3 Base Score 9,1/10 [CVE-2026-44758]
-
Privilege Escalation vulnerability in SAP ABAP Developer Tools (3772411): SAP ABAP Development Tools does not perform necessary authorization checks for certain functionality, allowing an attacker with low privileges to execute unauthorized database operations against SAP NetWeaver AS ABAP. Successful exploitation could allow the attacker to read sensitive data, modify application data, and disrupt access for legitimate users, resulting in high impact on confidentiality, integrity, and availability. A temporary workaround is available. CVSS v3 Base Score 8,8/10 [CVE-2026-58243]
-
Potential buffer overflow vulnerability affects SAP Commerce Cloud in public‑cloud deployments with NGINX (3773203): An unauthenticated attacker could send specially crafted requests that could trigger memory corruption in an internal process. Exploitation depends on conditions outside the attacker’s control, and on systems where standard memory protections are bypassed. Successful exploitation could lead to arbitrary code execution, resulting in high impact on confidentiality integrity and availability. CVSS v3 Base Score 8,1/10 [CVE-2026-42945]
-
Credentials disclosure in SAP BusinessObjects Business Intelligence Platform (Central Management Server) (3756565): SAP BusinessObjects Business Intelligence Platform stores certain sensitive credentials associated with user objects using a hard-coded cryptographic key. An attacker with high privileges and local access to the server could retrieve these objects and decrypt the stored credentials. Successful exploitation could allow the attacker to obtain sensitive authentication data and modify protected information, resulting in a high impact on confidentiality and integrity. CVSS v3 Base Score 7,9/10 [CVE-2026-66763]
-
Remote Code Execution vulnerability in Enhanced Change and Transport System (CTS+) Attach Tool (ctsattach) (3773304): Enhanced Change and Transport System (CTS+) attach tool (ctsattach) allows an authenticated attacker to supply a specially crafted archive file which, when processed by the application’s library, can trigger insecure deserialization and lead to remote code execution (RCE) on the system. Successful exploitation requires a victim to process the malicious archive, enabling the attacker to execute the RCE and extract sensitive information and gain control over the system and its processes. This vulnerability has a high impact on confidentiality and integrity of the data, with a low impact on the availability of the system. CVSS v3 Base Score 7,6/10 [CVE-2026-58233]
-
Directory Traversal vulnerability in SAP Manufacturing Integration and Intelligence (3759854): SAP Manufacturing Integration and Intelligence allows a privileged attacker to exploit insufficient file path validation in certain functions using specially crafted input. Exploitation also requires a legitimate user to subsequently access the attacker-influenced content and depends on conditions outside the attacker’s control. Successful exploitation could allow files to be written outside the intended directory and affect other components, resulting in a high impact on confidentiality, integrity, and availability. A temporary workaround is available. CVSS v3 Base Score 7,6/10 [CVE-2026-44763]
-
Missing Authorization Check in SAP Manufacturing Integration and Intelligence (3758657): Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence, an unauthenticated remote attacker could access scheduling-related application functions without proper authorization validation. Successful exploitation could allow the attacker to retrieve, create, modify, or delete application-managed scheduling data, causing a low impact on confidentiality, integrity, and availability. CVSS v3 Base Score 7,3/10 [CVE-2026-44765]
-
Missing Authorization Check in SAP Manufacturing Integration and Intelligence (3758910): Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence, an unauthenticated attacker could send crafted requests to the Cost Servlet using specific parameter values. If processed by the application, these requests enable access to backend operations. Successful exploitation could allow the attacker to read, create, modify, or delete application-managed business data, resulting in a limited impact on the confidentiality, integrity, and availability of the affected system. CVSS v3 Base Score 7,3/10 [CVE-2026-44764]
-
Multiple vulnerabilities in SAP Business AI Platform (Approuter) (3786038): This SAP security note addresses several vulnerabilities identified in SAP Approuter. The most critical is an Information Disclosure vulnerability where an unauthenticated attacker could send a specially crafted token to cause sensitive credential material to be sent to an attacker-controlled destination, resulting in a high impact on confidentiality and a low impact on integrity and availability. A temporary workaround is available. CVSS v3 Base Score 7,0/10 [CVE-2026-58230]
Reference links
References, in English, from SAP and Onapsis:
Affected resources
The full list of affected systems/components is as follows:
-
SAP Commerce Cloud (and Data Hub Adapter): COM_CLOUD 2211, 2211-JDK21, DHUB_CLOUD 2211
-
SAP Manufacturing Integration and Intelligence: XMII 15.4, 15.5, MII_ADMIN 15.4, 15.5
-
SAP NetWeaver and ABAP Platform: KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT, 7.22EX2, 7.22EX3, 7.53, 7.54, 7.77, 7.89, 7.93, 8.04, 9.16, 9.18, 9.19, KERNEL 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 8.04, 9.16, 9.18, 9.19
-
SAP ABAP Developer Tools: SAP_BASIS 750, 751, 752, 753, 754, 755, 756, 757, 758, 816, 918, 920
-
SAP BusinessObjects Business Intelligence Platform (Central Management Server): ENTERPRISE 430, 2025, 2027
-
Enhanced Change and Transport System (CTS+) Attach Tool (ctsattach): CTS_UPLOAD_CLT 1
-
SAP Business AI Platform (Approuter): <23.0.0




