CVE-2026-44764: Missing Authorization Check in SAP Manufacturing Integration and Intelligence
Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence, an unauthenticated attacker could send crafted requests to the Cost Servlet using specific parameter values. If processed by the application, these requests enable access to backend operations. Successful exploitation could allow the attacker to read, create, modify, or delete application-managed business data, resulting in a limited impact on the confidentiality, integrity, and availability of the affected system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-44764?
CVE-2026-44764 has a severity rating of high with a score of 7.3.
How do I fix CVE-2026-44764?
To fix CVE-2026-44764, apply the relevant security patch provided by SAP for the Manufacturing Integration and Intelligence.
What type of attacks can CVE-2026-44764 facilitate?
CVE-2026-44764 can facilitate unauthorized access to backend operations by allowing unauthenticated attackers to send crafted requests to the Cost Servlet.
Which software is affected by CVE-2026-44764?
The affected software is SAP Manufacturing Integration and Intelligence.
When was CVE-2026-44764 published?
CVE-2026-44764 was published on August 11, 2026.