Part of Lyceum Intelligence — deep-research In Focus reports → · Lyceum Corpus — ask the documents →

Full-text search across 381 articles. Typo-tolerant.

CVE-2026-44748 -- CVSS 9.9 Vulnerability Briefing

CVE-2026-44748 | CVSS 9.9 (Critical) | Exploit: No known exploit

What Is It

CVE-2026-44748 is an XML signature wrapping or signature bypass vulnerability affecting SAP NetWeaver Application Server ABAP and the ABAP Platform, allowing an authenticated attacker to manipulate signed XML documents accepted by the verifier.

Technical Detail

The flaw exists in the way SAP NetWeaver AS ABAP processes signed XML messages: an authenticated user with standard (non-privileged) credentials can capture a valid signed message and then modify its content while preserving or reusing the original signature in a way the verifier accepts as legitimate. This constitutes an XML signature wrapping attack, where the integrity guarantee of the signed document is effectively nullified. Successful exploitation could allow the attacker to inject unauthorized data, escalate privileges, or impersonate trusted system components depending on how the signed messages are consumed downstream, which accounts for the near-maximum CVSS score of 9.9.

Exploitation Status

No known exploit exists for this vulnerability at this time. The exploit maturity is currently assessed as zero, meaning no public proof-of-concept code or observed in-the-wild exploitation has been confirmed. This CVE is not listed in the CISA Known Exploited Vulnerabilities catalog as of June 16, 2026. The absence of a known exploit does not reduce the urgency of patching given the critical severity rating and the low privilege requirement for exploitation.

Who Is Targeting This

No specific threat actor attribution at this time. Neither confirmed nor reported threat actor associations have been established for this CVE. Organizations should note that SAP NetWeaver environments are historically targeted by financially motivated actors and state-sponsored groups pursuing enterprise resource planning data, and the low barrier to exploitation (normal authenticated user) makes this a plausible target of interest once exploitation techniques mature.

What To Do

Apply the relevant SAP Security Note addressing CVE-2026-44748 as a priority patch, treating the 9.9 CVSS score and low privilege requirement as the primary risk drivers. Organizations should consult the SAP Support Portal for the specific Security Note number and patch package applicable to their NetWeaver AS ABAP version and ABAP Platform release. As an interim measure, restrict the ability of low-privileged users to interact with XML signing and verification interfaces where operationally feasible, and audit access controls on services that consume signed XML messages. Monitor SAP application logs for anomalous XML message submissions from standard user accounts. Because this CVE is not currently KEV-listed, there is no CISA-mandated remediation deadline, but patching within a standard critical patch cycle of 30 days or fewer is advisable given the severity and attack surface.

All analysis →

Deep-research intelligence reports from Lyceum Intelligence — structured assessments with sourced claims and calibrated conclusions.

Browse Intelligence Reports →