A newly disclosed vulnerability tracked as CVE-2026-44756 and named OVERPASS lets unauthenticated attackers seize full control of SAP systems. Onapsis Research Labs, which found the flaw, says a single kernel patch is the only complete fix.
SAP has released an emergency fix for a vulnerability rated at the maximum possible severity score, after researchers at Onapsis found a way to run arbitrary operating system commands on SAP systems without a password. The flaw, tracked as CVE-2026-44756 and dubbed OVERPASS, sits in shared kernel code and can be reached through three separate routes, meaning no single network control can fully block it.
According to Onapsis Research Labs, which discovered and responsibly disclosed the issue to SAP, the vulnerability lies in how the SAP kernel processes the Extended Passport (EPP), a tracing structure SAP itself describes as a way to analyze call sequences across distributed system landscapes. Because EPP processing is shared across protocols, the flaw can be triggered from the internet-facing web layer, from the SAP GUI layer every end user logs on through, and from the RFC layer that links SAP systems together.
SAP addressed the issue on September 8, 2026, as part of its regular Patch Day cycle, publishing Security Note 3747649. The vulnerability carries a CVSS score of 10.0, the highest possible rating, and requires no authentication to exploit. Onapsis says it has not observed active exploitation in the wild as of publication, though it continues to monitor the threat landscape.
Why timing matters
The reason authentication controls offer no protection is structural rather than a configuration gap: EPP is processed at the very start of a session, before SAP’s usual checks, including user locks, roles, authorization objects and logon policies, are evaluated. Onapsis describes this as the core reason patching, rather than access restriction, is the only complete remedy.
Successful exploitation would grant an attacker the same operating-system privileges as the account running SAP itself, according to the researchers, effectively equivalent to owning the system outright, with the ability to read stored credentials, move laterally to connected SAP systems, and modify application data, configuration and the SAP binaries.
Onapsis frames the business impact in four categories: sabotage, such as deploying ransomware or corrupting database-level data; espionage, including exfiltration of financial records, HR files and intellectual property; fraud, such as creating privileged users or altering vendor bank details to redirect payments; and regulatory exposure, since a breach of this kind could trigger mandatory incident reporting under frameworks including SOX, NIS2, GDPR, HIPAA or PCI-DSS.
Wide footprint, three exposure paths
The affected code sits in the SAP kernel underpinning SAP S/4HANA, ECC, SAP NetWeaver Application Server ABAP, SAP Web Dispatcher, BW/4HANA, Enterprise Portal, PI/PO and SAP Solution Manager, among other products, according to Onapsis. The firm recommends that organizations assume affected systems exist until an inventory proves otherwise.
Onapsis says a targeted internet scan identified more than 10,000 unique IP addresses presenting a public-facing SAP web interface, a figure the firm calls conservative because it excludes SAP Web Dispatcher instances that do not return an identifiable banner. Exposure is concentrated in the United States, Germany, India and China, spanning both on-premises and cloud environments, the researchers say.
A second, less visible route runs through the SAP GUI layer, which is rarely exposed to the internet but is, by design, reachable from most of an organization’s internal network, meaning an attacker who has already gained a foothold via phishing or a compromised VPN session is positioned to exploit it. A third route runs through RFC connections between SAP systems.
Echoes of past incidents
Onapsis compares OVERPASS to ICMAD, a set of vulnerabilities disclosed in 2022 that also resided in shared SAP kernel code and also scored a maximum 10.0. The firm also points to CVE-2020-6287 (RECON), which attackers reverse-engineered from a patch within roughly 72 hours, and to CVE-2025-31324, which Mandiant’s 2026 M-Trends report named the most exploited vulnerability of the previous year after it was weaponized before many organizations had patched.
Recommended response
Onapsis recommends organizations first inventory all SAP systems, including forgotten or non-production instances, against their kernel patch level, then prioritize patching internet-facing systems before moving to internal ones, which it stresses are not lower priority, only later in sequence. Where patching cannot happen immediately, the firm advises restricting network reachability and monitoring for exploitation attempts as an interim measure, alongside SAP’s own FAQ Note 3776034 and workaround guidance in Note 3756304.
Onapsis also notes that standard SAP access controls, including authorization roles and Segregation of Duties settings, have no bearing on this attack path, since the vulnerable code runs before any authentication check takes place. Organizations unable to patch immediately are advised to treat monitoring as a stopgap, not a substitute.
SAP and Onapsis will host a joint briefing on September 9, 2026, at 10:00 a.m. EDT regarding this and other vulnerabilities from the September Patch Day. You can register here: https://onapsis.com/event/sept-patch-day-26-vulns/?utm_campaign=2026-Q3-global-septsapwebinar&utm_medium=website&utm_source=onapsis&utm_content=blogreg

Dr. Jakob Jung is Editor-in-Chief of Security Storage and Channel Germany. He has been working in IT journalism for more than 20 years. His career includes Computer Reseller News, Heise Resale, Informationweek, Techtarget (storage and data center) and ChannelBiz. He also freelances for numerous IT publications, including Computerwoche, Channelpartner, IT-Business, Storage-Insider and ZDnet. His main topics are channel, storage, security, data center, ERP and CRM.
Contact via Mail: jakob.jung@security-storage-und-channel-germany.de