CVE-2026-44748

Published Jun 9, 2026

Last updated 11 days ago

Overview

Description
SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated attacker with normal privileges to obtain a valid signed message and send modified signed XML documents to the verifier. This may result in acceptance of tampered identity information leading to unauthorized access to sensitive user data and potential disruption of normal system usage. This causes a high impact on confidentiality, integrity and availability of the application.
Source
cna@sap.com
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.9
Impact score
6
Exploitability score
3.1
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

cna@sap.com
CWE-347

Social media

Hype score
Not currently trending
  1. ثغرة حرجة في خوادم ساب تتيح للمهاجم تزوير الهوية وتجاوز المصادقة بالكامل المعرّف : CVE-2026-44748 درجة الخطورة : 9.9 (CVSS) - Critical الإصدارات المتأثرة : SAP NetWeaver AS ABAP / A

    @KasperskyDev

    15 Jun 2026

    59 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. SAP June Patch Day: 15 security notes, 4 critical. CVE-2026-44748 (CVSS 9.9) — XML Signature Wrapping bypass in NetWeaver SAML. CVE-2026-27671 (CVSS 9.8) — unauthenticated memory corruption in ABAP RFC gateway. https://t.co/URyHYrF8Aa #CyberSecurity #Vulne https://t.co/vngyJi

    @securitydailyr

    11 Jun 2026

    40 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. SAP Security Patch Day June 2026: Critical CVE-2026-44748 SAML Flaw Could Allow Full Authentication Bypass https://t.co/19RvwBdR5H SAP Security Patch Day June 2026: Critical CVE-2026-44748 SAML Flaw Could Allow Full Authentication Bypass On June 9, 2026, SAP released its mont

    @f1tym1

    10 Jun 2026

    30 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. 🚨 NEW: SAP June Patch Day — 4 critical flaws, top CVSS 9.9. The worst: CVE-2026-44748 lets a low-privileged user forge SAML assertions and bypass authentication entirely on NetWeaver ABAP. CVE-2026-27671 (CVSS 9.8) is unauthenticated memory corruption via crafted RFC request

    @CyberAlertsHQ

    9 Jun 2026

    75 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  5. SAP released 15 security notes addressing four critical flaws including CVE-2026-44748 and CVE-2026-27671 in NetWeaver and other core products, Belgium's Centre for Cybersecurity said. https://t.co/V0QlgiVYvz

    @threatcluster

    9 Jun 2026

    21 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. Warning: #SAP has released security updates for 15 vulnerabilities in several of their products, including 4 critical vulnerabilities: #CVE-2026-44748; #CVE-2026-27671; #CVE-2026-40128 and #CVE-2026-22732. Read our advisory here: https://t.co/cVlLvwsEYZ #Patch #Patch #Patch

    @CCBalert

    9 Jun 2026

    107 Impressions

    2 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. 🚨Critical - Two SAP NetWeaver Flaws Patched in June 2026 (CVE-2026-44748, CVE-2026-40128) SAP's June 2026 Security Patch Day fixes two critical SAP NetWeaver vulnerabilities, both with a scope change and full C/I/A impact. CVE-2026-44748 (9.9) - AS ABAP and ABAP Platform: an

    @UpwindMDR

    9 Jun 2026

    128 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. 🚨 CVE-2026-44748 — CVSS 9.9/10 ██████████ SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated attacker with normal privileges to... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/QkbkF2xXiX

    @OrizonCyber

    9 Jun 2026

    88 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

References

Sources include official advisories and independent security research.