CVE-2026-44763

Summary

SAP Manufacturing Integration and Intelligence allows a privileged attacker to exploit insufficient file path validation in certain functions using specially crafted input. Exploitation also requires a legitimate user to subsequently access the attacker-influenced content and depends on conditions outside the attacker�s control. Successful exploitation could allow files to be written outside the intended directory and affect other components, resulting in a high impact on confidentiality, integrity, and availability.

Affected Software

VendorProductVersion RangeStatus
SAP_SESAP Manufacturing Integration and IntelligenceXMII 15.4affected
SAP_SESAP Manufacturing Integration and Intelligence15.5affected

Weaknesses

  • CWE-22: CWE-22: Improper Limitation of a Pathname to a Restricted Directory

References