Sceawere
Vulnerability Detail
CVE-2026-44763UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
SAP MII File Path Traversal
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.6
- Creation Date
- 4h ago
- Vendor
- SAP_SE
- Product
- SAP Manufacturing Integration and Intelligence
- Attack Type
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H
- Attack Complexity
- HIGH
Narrative and Response
Description
SAP Manufacturing Integration and Intelligence allows a privileged attacker to exploit insufficient file path validation in certain functions using specially crafted input. Exploitation also requires a legitimate user to subsequently access the attacker-influenced content and depends on conditions outside the attacker�s control. Successful exploitation could allow files to be written outside the intended directory and affect other components, resulting in a high impact on confidentiality, integrity, and availability.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.6",
"pubDate": "2026-08-11T01:17:20.930Z",
"pubdate": "2026-08-11T01:17:20.930Z",
"executiveSummary": "SAP Manufacturing Integration and Intelligence is affected by an insufficient file path validation vulnerability that enables privileged threat actors to execute arbitrary file write operations outside the intended directory structure. This vulnerability poses a severe risk to organizational infrastructure, resulting in a high impact on confidentiality, integrity, and availability by potentially compromising other system components.\nThe exploitation of this flaw requires a privileged attacker capable of supplying specially crafted input to vulnerable functions within the application. Furthermore, successful end-to-end exploitation is contingent upon external conditions outside the direct control of the attacker, specifically requiring a legitimate user to subsequently access the attacker-influenced content.\nGiven the severity of the potential impact on core triad security principles, organizations utilizing the affected product must prioritize risk management through strict access controls, input validation hardening, and continuous monitoring of file system modifications.",
"technicalDetails": "The root cause of the vulnerability stems from insufficient file path validation within specific functions of SAP Manufacturing Integration and Intelligence. When the application processes user-supplied input intended for file system operations, it fails to adequately sanitize or restrict directory traversal sequences, allowing input containing relative path indicators to manipulate the intended destination directory.\nThe attack flow requires the attacker to possess elevated privileges within the application environment. The attacker initiates the exploitation vector by submitting specially crafted input designed to bypass or exploit the inadequate path validation logic during specific function executions. This allows the attacker to target file write operations outside the designated sandbox or intended directory.\nBecause the payload behavior relies on secondary interaction, the malicious or attacker-influenced content written to the file system must subsequently be accessed by a legitimate user of the system. This dependency introduces conditions outside the attacker's direct control, acting as a prerequisite for the full realization of the attack vector.\nUpon successful execution and subsequent access by a legitimate user, the post-exploitation impact includes unauthorized modification, extraction, or destruction of critical system files. This compromise extends beyond the immediate application context, severely impacting confidentiality, integrity, and availability across other integrated system components."
}