Sceawere

Vulnerability Detail

CVE-2026-44764UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

SAP MII Cost Servlet Authorization Bypass

Vulnerability Metadata

Severity
High
Score / CVSS
7.3
Creation Date
4h ago
Vendor
SAP_SE
Product
SAP Manufacturing Integration and Intelligence
Attack Type
CWE-862: Missing Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence, an unauthenticated attacker could send crafted requests to the Cost Servlet using specific parameter values. If processed by the application, these requests enable access to backend operations. Successful exploitation could allow the attacker to read, create, modify, or delete application-managed business data, resulting in a limited impact on the confidentiality, integrity, and availability of the affected system.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.3",
  "pubDate": "2026-08-11T01:17:21.053Z",
  "pubdate": "2026-08-11T01:17:21.053Z",
  "executiveSummary": "A Missing Authorization Check vulnerability has been identified in SAP Manufacturing Integration and Intelligence. The flaw exists within the Cost Servlet component, allowing unauthenticated remote threat actors to interact with backend operations by supplying specifically crafted parameter values within HTTP requests. Successful exploitation of this vulnerability grants unauthorized actors the ability to perform full CRUD operations—reading, creating, modifying, and deleting—on application-managed business data. While the scope of the impact is technically confined to the application layer rather than the underlying operating system, the compromise of critical business data leads to a tangible reduction in confidentiality, integrity, and availability. The attack vector requires network connectivity to the affected SAP Manufacturing Integration and Intelligence service, but does not necessitate prior authentication or specialized privileges, lowering the complexity barrier for potential adversaries. Organizations utilizing vulnerable versions of the software face significant risk regarding data integrity and business continuity due to the exposure of sensitive backend transactional processes.",
  "technicalDetails": "The vulnerability is rooted in an insufficient access control implementation within the routing and permission validation logic of SAP Manufacturing Integration and Intelligence. Specifically, the Cost Servlet fails to properly enforce session validation or role-based access control checks prior to processing incoming HTTP requests directed at sensitive backend functional routines.\nThe attack flow initiates when an unauthenticated remote attacker crafts a specialized HTTP request containing targeted parameter values designed to interface with the Cost Servlet. Because the servlet lacks adequate authorization validation primitives, it processes the incoming payload and routes the execution flow directly to underlying backend operations that should otherwise be strictly restricted to authenticated and authorized administrative or operational personnel.\nThe vulnerable component is the Cost Servlet integrated within SAP Manufacturing Integration and Intelligence. The attack vector is network-based, exposing the endpoint to any entity capable of reaching the application's HTTP/HTTPS service ports. No prior authentication, user credentials, or specific privilege levels are required by the attacker to successfully transmit the malicious parameters and trigger the flaw.\nUpon successful processing of the crafted request by the application logic, the payload behavior enables unauthorized transactional execution against backend data structures. Post-exploitation impact encompasses the complete compromise of application-managed business data. The attacker can execute unauthorized read operations to harvest sensitive metrics, create fraudulent entries, modify existing operational configurations or financial data, and delete critical business records. This directly undermines the confidentiality, integrity, and availability posture of the affected SAP Manufacturing Integration and Intelligence deployment without necessarily triggering standard application-level authentication alerts."
}
CVE-2026-44764: SAP MII Cost Servlet Authorization Bypass (HIGH Severity, CVSS: 7.3) - Sceawere