SAP OVERPASS CVE-2026-44756: unauth OS command exec on NetWeaver/Web Dispatcher

By George Bailey   Published: 09/10/26   Updated: 09/10/26   3 min read

What Changed

SAP’s September 2026 Patch Day, with Onapsis Research Labs, shipped Security Note 3747649 for OVERPASS (CVE-2026-44756): a memory-corruption bug in SAP Extended Passport (EPP) processing. Missing boundary validation during deserialization of externally supplied length fields lets an unauthenticated attacker send crafted network requests—malformed EPP / sap-passport-style headers—that corrupt kernel memory. Impact per SAP and Onapsis runs through arbitrary operating-system command execution under the SAP administrative OS account. The defective code sits in shared kernel paths used by ICM / NetWeaver ABAP and Java kernels and SAP Web Dispatcher 9.16 (other Web Dispatcher versions and HANA XS–bundled Web Dispatcher are called out as not affected in Onapsis’s summary). No credentials are required; the vulnerable path runs before authorization controls apply.

Same-cycle companion: S4GET (CVE-2026-58240, Note 3759472, CVSS 9.8)—a missing authentication check in the NetWeaver Message Server when registering internal application-server components. It affects modern 9.16 / 9.18 / 9.19 / 9.20 kernels. Onapsis notes the trigger rides the same public port SAP GUI clients use, so firewalling it without breaking logon is impractical.

Exposure estimate (labeled as estimate): Onapsis commentary relayed by BleepingComputer cites more than 10,000 unique Internet-facing IPs presenting an SAP web interface—described as conservative because it counts HTTP-reachable systems and undercounts Web Dispatcher. This is an Onapsis estimate, not a confirmed victim count, and primary coverage does not claim in-the-wild exploitation at disclosure.

Why This Matters Operationally

ERP kernels and Web Dispatchers are the business plane. Unauthenticated OS command execution on that plane is ransomware- and espionage-grade impact without a phishing foothold first. Pairing OVERPASS with same-day S4GET makes September’s SAP Patch Day two pre-auth cluster-compromise classes on core NetWeaver plumbing—not “average HotNews volume.”

What Defenders Should Verify First

Source Context

George Bailey

George Bailey is a cybersecurity researcher and writer at CyberExperts, covering cyber threats, AI, cloud security, vulnerabilities, and defensive strategies. His goal is to help security professionals quickly understand what matters most and how it impacts their organizations.