Skip to content

SAP vulnerability “OVERPASS” may be its worst ever

SAP kernel bug, CVSS 10, has "fight for patching downtime asap" written all over it. Who's affected?

SAP vulnerability “OVERPASS” may be its worst ever

A critical SAP vulnerability, allocated CVE-2026-44756 and dubbed “OVERPASS”, affects potentially most of the entire installed SAP user base, can be exploited remotely without authentication (CVSS 10), can’t be trivially mitigated and immediately affects a conservative 10,000 publicly exposed customers.

SAP has a patch out today. The vulnerability, which was disclosed by SAP security specialist Onapsis to the ERP giant in late April, is in SAP’s shared kernel code and can be attacked/is reachable from the Internet-facing web layer (HTTP), from the SAP GUI layer every end user connects to, and from the RFC layer that links SAP systems.

That’s according to Onapsis today, which said the vulnerable code is in “the majority of SAP’s business software… anything running on that kernel inherits the flaw.” 

"All kernel versions are affected. The SAP Note just lists kernel versions that are still in maintenance." – SAP Security Note 374764

In a bid to slow efforts by bad actors (or ambitious security researchers) to reverse the patch and generate a POC, Onapsis has shared no exploit chain details, merely noting blandly that the bug is in the “processing of the Extended Passport (EPP), the standard SAP tracing structure that clients attach to their requests…”

SAP Security Note 3747649 has more detail on which builds are affected.

Onapsis CTO Juan Perez Etchegoyen described the vulnerability to us as probably “the most widespread vulnerability we have seen ” and said he expects patch diff analysis by bad actors to result in a public proof-of-concept exploit and attacks to follow. 

(SAP NetWeaver, CVE-2025-31324, was the most frequently-exploited vulnerability last year, according to Mandiant’s M-Trends report, so this is a big target.)

Etchegoyen told The Stack on a call: “This [exposes] pretty much [the] entire SAP population, because this affects SAP NetWeaver Java, SAP NetWeaver ABAP [etc.]. Even systems that are not internet-facing are also exposed to be exploited internally.”

(Onapsis says that the exploitable surface “extends across SAP S/4HANA, SAP ERP and the SAP Business Suite (ECC), SAP NetWeaver Application Server ABAP, the SAP Web Dispatcher, SAP BW/4HANA, SAP Enterprise Portal, SAP PI/PO, SAP Solution Manager, and the many other solutions built on the same kernel… the correct starting assumption is that at least some systems are in scope until proven otherwise.”) 

We keep our security reporting free out of public interest. Subscribing gets you full access to exclusive interviews, a 50% discount on our event tickets, and a warm fuzzy glow for supporting independent journalism at a bootstrapped, management-owned publication.

You can support us here

In a blog on the vulnerability, he emphasised firmly that “SAP authorizations and Segregation of Duties (SoD) controls will not help. The vulnerable code runs before any authentication step, so locking users, tightening roles, enforcing password policies or restricting transaction access has no effect on this attack path…”

“A targeted search using high-fidelity fingerprints identifies more than 10,000 unique Internet-facing IP addresses presenting an SAP web interface reachable from the public Internet, and that figure is conservative. It counts only HTTP-reachable systems and materially undercounts the SAP Web Dispatcher, which proxies its backend and returns no distinguishing SAP banner on its root path,” Onapsis added today. 

Its CTO told The Stack: “Patching the kernel is technically simple because you swap a set of binaries for another. But getting that downtime on each one of those systems at the core of the business processes-? That's where it's really complex, right?”

Was the bug found with AI? 

“We have a lot of internal tools and scripts that allows us to understand explore the different SAP technologies. On top of that, we have built MCPs and skills and basically a harness to research SAP technology. [Our] researchers pick a specific research project, and they start analysing it using AI as part of it, but also understanding how it works, using it as an end user, and once those things combine, AI provides a list of potential targets. They analyze them. They triage, compare…There is this backbone of AI driven through harnesses that allows us to to be more effective,” he adds.

There’s more bad news in SAP’s Patch Tuesday, including another pre-auth RCE, CVSS 9.8 bug found by his team dubbed S4GET (allocated CVE-2026-58240). This affects the Message Server in specific versions of SAP S/4HANA and allows an attacker to gain access to the entire SAP system cluster and remotely execute malicious payloads. It’s a missing authentication issue; attackers need network access and that’s it. 

The big challenge right now for security teams: Persuading their employers that systems at the very heart of many mission-critical enterprise processes need downtime for swift remediation. Can they do so before an exploit, and attacks land?

We’re about to find out.

The Pentester’s 0days: What (exploited) VMware bugs say about the changing face of infosec

Add The Stack on Google