SAP has patched a maximum-severity vulnerability in its Extended Passport (EPP) Processing component that could let an unauthenticated attacker take control of a wide range of SAP systems before a user even logs in, according to application security firm Onapsis.
A Flaw Reached Before Security Checks Apply
The vulnerability, tracked as CVE-2026-44756 and rated a maximum CVSS score of 10, stems from missing boundary validation during the deserialization of EPP data, which is used for tracing across multiple SAP applications. Onapsis, which dubbed the flaw OVERPASS, says it is triggered as soon as a new user session opens, meaning it executes before any of SAP’s access controls, including user locks, roles, authorization objects and logon policies, ever get a chance to evaluate the connection. “None of them is in the attacker’s way,” Onapsis said.
The flaw resides in SAP’s kernel code and can be reached through at least three separate paths: standard web requests, the SAP GUI protocol, and Remote Function Call connections. Because the vulnerable code runs under the operating-system account that owns the SAP installation, Onapsis says successful exploitation is equivalent to gaining full control of the SAP system, allowing an attacker to run arbitrary system commands, recover database credentials and password hashes, read the live sessions of logged-in users, and modify data, configurations and SAP binaries.
Broad Product Exposure, No Known Exploitation Yet
The vulnerable kernel code underlies a wide range of SAP products, including S/4HANA, ERP, Business Suite (ECC), NetWeaver, Web Dispatcher, BW/4HANA, Enterprise Portal, PI/PO and Solution Manager. Neither Onapsis nor SAP has reported evidence that the flaw has been exploited in the wild.
SAP released the fix as part of 20 new and updated security notes issued on its September 2026 Patch Day. Three other critical vulnerabilities were resolved in the same release: CVE-2026-58240, a missing authentication check in NetWeaver; CVE-2026-76969, a credential disclosure issue in multitenant applications using the Cloud Application Programming Model; and CVE-2026-66768, an improper access control flaw in NetWeaver. SAP customers running any of the affected products are advised to apply the September patches as a priority given the pre-authentication nature of the OVERPASS flaw.









