CVE-2026-44758
Last modified
CVE-2026-44758 is a critical-severity vulnerability rated 9.1/10 on the CVSS scale. SAP Manufacturing Integration and Intelligence (MII) allows an attacker with high privileges to submit specially crafted input to certain affected functionality, which is processed without sufficient validation. Successful exploitation could allow the attacker to execute arbitrary commands on the underlying operating system, resulting in high impact on confidentiality, integrity, and availability of the application.. EPSS estimates a 0.51% chance of exploitation in the next 30 days.
Description
SAP Manufacturing Integration and Intelligence (MII) allows an attacker with high privileges to submit specially crafted input to certain affected functionality, which is processed without sufficient validation. Successful exploitation could allow the attacker to execute arbitrary commands on the underlying operating system, resulting in high impact on confidentiality, integrity, and availability of the application.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| SAP_SE | SAP Manufacturing Integration and Intelligence | XMII 15.4; 15.5 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-44758?
How severe is CVE-2026-44758?
How do I fix CVE-2026-44758?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-44751Application server ABAP does not perform necessary authoriza…7.1
- CVE-2026-44752SAP NetWeaver Application Server Java allows an unauthentica…8.2
- CVE-2026-44753SAP HANA Database (user self service tools) allows an unauth…3.7
- CVE-2026-44754The Remote Function Call (RFC) modules of the Operational Da…6.6
- CVE-2026-44755SAP Business Objects Business Intelligence Platform does not…4.3
- CVE-2026-44757SAP Wily Introscope Enterprise Manager allows an unauthentic…4.7
- CVE-2026-44759SAP NetWeaver Enterprise Portal allows an unauthenticated at…6.1
- CVE-2026-4476A vulnerability was found in Yi Technology YI Home Camera 2 …6.3
- CVE-2026-44760Due to a Cross-Site Scripting (XSS) vulnerability, applicati…4.7
- CVE-2026-44761SAP Commerce Cloud could retain a sample OAuth2 client with …9.1
- CVE-2026-44762SAP Data Services Management Console allows an overly permis…3.7
- CVE-2026-44763SAP Manufacturing Integration and Intelligence allows a priv…7.6
Are you affected by CVE-2026-44758?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
