CVE-2026-76971: Server-Side Request Forgery in SAP Manufacturing Integration and Intelligence
Due to a Server-Side Request Forgery (SSRF) vulnerability in SAP Manufacturing Integration and Intelligence, an attacker could cause the server to initiate arbitrary outbound requests. If processed by the application, this behavior could be combined with XML/XSL processing to enable execution of scripts. Successful exploitation could result in a low impact on the confidentiality, integrity, and availability of the application.
Affected Software
Event History
Frequently Asked Questions
What access and interaction does an attacker need to exploit this issue?
The severity vector indicates that exploitation is network-accessible, has low attack complexity, requires low privileges, and requires user interaction. The attack can cause the server to make arbitrary outbound requests.
What could make the impact worse than outbound requests alone?
If the application processes the SSRF-triggered behavior together with XML/XSL processing, the issue could enable script execution. The stated impact is low confidentiality, integrity, and availability impact.
How can I determine whether my environment is affected?
The affected software identified is SAP Manufacturing Integration and Intelligence. Review SAP Note 3786489 for product-specific remediation and applicability information.