A CVSS 9.1 code injection flaw in SAP Manufacturing Integration and Intelligence (MII) lets a high-privileged attacker execute arbitrary operating system commands on the underlying host.
What Is It
CVE-2026-44758 is a code injection vulnerability (CWE-94) in SAP Manufacturing Integration and Intelligence. Certain affected functionality accepts specially crafted input and processes it without sufficient validation. An attacker holding high privileges can abuse this to execute arbitrary commands on the underlying operating system, with high impact on confidentiality, integrity, and availability.
The CVSS 3.1 base score is 9.1 (CRITICAL), vector CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H. SAP SE is the assigning CNA. The record carries a publication date of 2026-08-11, one day ahead of this brief, and its NVD status is "Received," so the details below reflect the CNA-supplied record as it currently stands rather than a settled, fully enriched entry. Fields including affected-version lists and reference material may change as the record is analyzed.
Why It Matters
The severity comes from where the attack lands, not how hard it is to reach. Attack vector is network with low complexity and no user interaction required. The scope is changed, exploitation breaks out of the application's security boundary and reaches the host operating system, which is what pushes this to 9.1 despite the high-privilege prerequisite.
MII sits at the seam between business systems and plant-floor operations. OS-level command execution on that host is a meaningful foothold in an environment that typically bridges IT and manufacturing networks.
The high privileges required is the one real mitigating factor: an attacker needs an existing privileged account on the MII instance before any of this is reachable.
CVE-2026-44758 does not appear in the CISA Known Exploited Vulnerabilities Catalog as of this writing, so active exploitation is not confirmed at this time.
What's Vulnerable
Per SAP's CNA record, the following versions of SAP Manufacturing Integration and Intelligence are affected:
- XMII 15.4
- 15.5
Default status for all other versions is listed as unaffected. No CPE entries accompany the record.
Patch Status
The record ties this disclosure to SAP's Security Patch Day cycle and points to SAP Note 3758900 as the authoritative source for the fix and any workarounds. Access requires SAP customer credentials. Administrators running XMII 15.4 or 15.5 should check that note for availability and apply it once accessible, and in the interim audit which accounts hold the high-privilege roles that make exploitation possible.
No specific required-action deadline is present in the supplied data.
Sources
- SAP Note 3758900; https://me.sap.com/notes/3758900
- SAP Security Patch Day; https://url.sap/sapsecuritypatchday
- NVD, CVE-2026-44758 (source: [email protected], publication date 2026-08-11)
- CISA Known Exploited Vulnerabilities Catalog; https://www.cisa.gov/known-exploited-vulnerabilities-catalog