- Description
- SAP Manufacturing Integration and Intelligence (MII) allows an attacker with high privileges to submit specially crafted input to certain affected functionality, which is processed without sufficient validation. Successful exploitation could allow the attacker to execute arbitrary commands on the underlying operating system, resulting in high impact on confidentiality, integrity, and availability of the application.
- Source
- cna@sap.com
- NVD status
- Received
CVSS 3.1
- Type
- Secondary
- Base score
- 9.1
- Impact score
- 6
- Exploitability score
- 2.3
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
- Severity
- CRITICAL
- cna@sap.com
- CWE-94
- Hype score
- Not currently trending
Warning: multiple critical code injection, out-of-bounds write in #SAP #commercecloud #netweaver #MII CVE-2026-58231, CVE-2026-44772, CVE-2026-34265 & CVE-2026-44758 CVSS: 10-9.1 The first one is actively exploited #Patch #Patch #Patch
@CCBalert
18 Aug 2026
238 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 NUEVA CVE: CVE-2026-44758 — SAP MII (Command Injection) ⚠️ CVSS 9.1 (CRÍTICO) · publicada el 11/08/2026 Afectados: Instâncias SAP MII com usuários de privilégios altos Entrada maliciosa proce https://t.co/9MrjUBolzp
@Douglas01284182
13 Aug 2026
7 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 NEW CVE: CVE-2026-44758 — SAP MII (Command Injection) ⚠️ CVSS 9.1 (CRITICAL) · published Aug 11, 2026 Affected: Instâncias SAP MII com usuários de privilégios altos Entrada maliciosa processa https://t.co/ntCMeLel8W
@Douglas01284182
13 Aug 2026
8 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
SAP issued its August 2026 Patch Tuesday release with 28 advisories, four rated Critical. CVE-2026-58231 in SAP Commerce Cloud Data Hub Adapter scores CVSS 10.0 due to authorization bypass. Two code injection flaws (CVE-2026-44772, CVE-2026-44758) affect SAP Manufacturing
@WorldCyberNewsX
13 Aug 2026
4 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes