CVE-2026-76958: XML External Entity (XXE) Vulnerability in SAP Integration Suite

Published Sep 8, 2026
·
Updated

SAP Integration Suite does not sufficiently validate XML documents accepted from untrusted sources in certain internal components. An attacker with low privileges could submit specially crafted XML payloads containing malicious external entity declarations. Successful exploitation could allow the attacker to read sensitive file contents from the server and expose them through monitoring or logging output, resulting in a high impact on confidentiality. It could also lead to resource exhaustion, causing a low impact on availability. There is no impact on integrity.

Affected Software

1 affected component
SAP SAP Integration Suite

Event History

Sep 8, 2026
CVE Published
via MITRE·12:11 AM
Data Sourced
via MITRE·12:11 AM
DescriptionSeverity

Frequently Asked Questions

1

Who can exploit this issue?

An attacker needs low privileges in SAP Integration Suite and must be able to submit XML documents to the affected internal components from an untrusted source. The issue is remotely exploitable and does not require user interaction.

2

What could an attacker obtain or disrupt?

A crafted XML payload with malicious external entity declarations could cause sensitive files on the server to be read and exposed through monitoring or logging output. It may also cause resource exhaustion, producing a low availability impact; integrity is not affected.

3

Is a default deployment known to be affected?

The available information identifies certain internal components that accept untrusted XML documents, but does not state whether those components are enabled or exposed in a default configuration.

4

How can I determine whether my environment is exposed?

Review whether low-privileged users can submit untrusted XML to SAP Integration Suite internal components and whether related monitoring or logging output could expose processed XML data. The provided information does not identify specific affected component names or versions.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203