Maximum-Severity SAP Flaw Lets Attackers Take Over Systems Without a Password
SAP has released updates fixing several vulnerabilities, the most serious being a maximum-severity flaw (CVE-2026-44756, CVSS 10.0) in how the SAP kernel processes Extended Passport (EPP) data. Discovered by security firm Onapsis and nicknamed OVERPASS, the bug is a memory corruption issue caused by missing validation checks when the system reads certain data fields.
What makes this flaw especially dangerous is that it requires no login credentials and can be triggered remotely. Attackers can send a specially crafted network request to exploit shared kernel code, which is reachable through multiple entry points including internet-facing web services, the standard SAP GUI used by everyday staff, and the connections linking different SAP systems together. According to Onapsis, this means no single firewall rule or network control can fully block the risk.
If exploited, attackers could gain administrative control of the SAP host, allowing them to steal stored credentials and password hashes, access live user sessions, move laterally across connected SAP systems, and alter business data, configurations, or core software files. Given the severity and ease of exploitation, organisations running SAP should prioritise applying the available patches without delay.