CVE-2026-44758 -- CVSS 9.1 Vulnerability Briefing
CVE-2026-44758 | CVSS 9.1 (Critical) | Exploit: PoC available
What Is It
CVE-2026-44758 is a critical OS command injection vulnerability in SAP Manufacturing Integration and Intelligence (MII) affecting certain functionality that processes insufficiently validated attacker-supplied input.
Technical Detail
An attacker with high privileges can submit specially crafted input to affected SAP MII functionality, where inadequate input validation enables command injection. Successful exploitation can result in remote code execution on the underlying operating system in the security context of the affected application or service. This can compromise the confidentiality, integrity, and availability of the SAP MII application and potentially the host system.
Exploitation Status
A proof of concept is available. This indicates that exploitation techniques have been publicly demonstrated or are available for testing, but active exploitation in the wild has not been confirmed. CISA has not listed this CVE in its Known Exploited Vulnerabilities catalog as of August 12, 2026.
Who Is Targeting This
No specific threat actor attribution at this time.
What To Do
Prioritize installation of SAP-provided fixes or security updates for affected SAP MII deployments. Restrict access to SAP MII administrative and high-privilege functionality to authorized users, enforce least-privilege access, and review privileged accounts for unnecessary permissions. Monitor SAP MII and host operating system logs for unusual command execution, unexpected child processes spawned by SAP services, anomalous administrative activity, and changes to application or system configuration. No vendor workaround or specific detection signature is confirmed in the available information.