Enterprise software giant SAP has released 22 Security Notes, highlighting a critical stack-based buffer overflow flaw dubbed OVERPASS that permits remote code execution across core infrastructure.
Enterprise security teams face an immediate patching priority following SAP’s latest security updates. Among 22 Security Notes and five HotNews entries released by the vendor, a single maximum-severity flaw identified as CVE-2026-44756—internally designated as OVERPASS—has emerged as a major threat to global corporate IT environments. Carrying a maximum Common Vulnerability Scoring System (CVSS) rating of 10.0, the flaw lies deep within the SAP Kernel’s Extended Passport Processing (EPP) library and allows unauthenticated threat actors to execute arbitrary commands with full administrative privileges.
The vulnerability targets the Extended Passport mechanism, a tracing tag attached to client requests designed to allow administrators to validate queries across interconnected systems before evaluating authorization details. By transmitting a specially crafted network request containing a malformed EPP header, an unauthenticated remote attacker can trigger a memory corruption event. This stack-based buffer overflow effectively hijacks the active process handling the incoming request, yielding complete system-level control over the host server. Consequently, successful exploitation grants unauthorized actors unhindered access to critical underlying business data, financial records, payroll systems, and supply chain operations.
Security experts emphasize that the attack surface created by OVERPASS is exceptionally broad. The affected EPP library forms a core component across nearly all primary SAP product suites, including S/4HANA, ERP, Business Suite (ECC), NetWeaver, Web Dispatcher, Business Warehouse (BW/4HANA), Enterprise Portal, Process Integration/Orchestration (PI/PO), and Solution Manager. Furthermore, the vulnerability can be reached via three distinct operational vectors: the HTTP web layer via the Internet Graphics Server or Web Dispatcher, the native SAP GUI layer, and the Remote Function Call (RFC) layer linking separate SAP deployments.
According to Mayuresh Dani, Security Research Manager at the Qualys Threat Research Unit (TRU), the multi-vector nature of OVERPASS creates a deceptive sense of security for isolated systems. “OVERPASS (CVE-2026-44756) is a stack-based buffer overflow vulnerability found in the Extended Passport Processing (EPP) library implemented in the SAP kernel. It allows remote attackers to execute arbitrary operating system commands on the SAP host with administrative SAP privileges, leading to a complete compromise of the underlying SAP business data and processes. The EPP provides a tracing tag that clients append to their requests so that administrators can validate a request across connected systems—even before authorization details are checked. An attacker can submit a malformed tag to take over the process handling the request and execute their own commands on the server.
Fortunately, there are no public exploits or PoCs to date. However, since the patch has already been released, it is expected that these will soon emerge based on the patch diff information, as SAP systems feature prominently on the CISA KEV list. Since the affected component is part of installations of S/4HANA, ERP, Business Suite (ECC), NetWeaver, Web Dispatcher, BW/4HANA, Enterprise Portal, PI/PO, and Solution Manager, it is important to patch all versions.”
While vendor-provided mitigation guidelines exist to temporarily reduce the HTTP attack surface, these measures fail to shield the internal GUI and RFC pathways. Because the SAP GUI pathway remains open by design on every application server, temporary workarounds offer incomplete protection, leaving patching as the only definitive solution.
While security researchers confirm that no active exploitation or public proof-of-concept (PoC) code has been detected in the wild to date, the window for proactive defense is closing rapidly. Historically, SAP vulnerabilities attract swift attention from malicious actors once patch-diffing analysis becomes possible. Given the prominent representation of SAP systems on the CISA Known Exploited Vulnerabilities (KEV) list, security teams expect functional exploits to surface shortly.
Remediation presents operational challenges for enterprise administrators. Applying a kernel-level patch typically necessitates a complete system reboot, a disruptive requirement for mission-critical environment routines. Security leaders recommend prioritizing immediate patch deployment on internet-facing systems, closely followed by internal infrastructure. In the interim, organizations should restrict exposure using SAProuter, jump hosts, and Web Dispatchers while maintaining vigilant monitoring for anomalous network activity across all endpoints.

Dr. Jakob Jung is Editor-in-Chief of Security Storage and Channel Germany. He has been working in IT journalism for more than 20 years. His career includes Computer Reseller News, Heise Resale, Informationweek, Techtarget (storage and data center) and ChannelBiz. He also freelances for numerous IT publications, including Computerwoche, Channelpartner, IT-Business, Storage-Insider and ZDnet. His main topics are channel, storage, security, data center, ERP and CRM.
Contact via Mail: jakob.jung@security-storage-und-channel-germany.de
