SAP SAPSPrint Service Buffer Overflow via Command Handling
CVE-2026-40130 Published on August 11, 2026
Memory Corruption vulnerability in SAPSPrint Service
SAP SAPSPrint Service has memory corruption vulnerabilities in the handling of certain commands. An unauthenticated attacker could send specially crafted requests that trigger a buffer overflow in the affected component. This causes a temporary service interruption and automatic restart, resulting in low impact on availability but no impact on confidentiality and integrity.
Vulnerability Analysis
CVE-2026-40130 is exploitable with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity, and a small impact on availability.
Weakness Type
What is a Stack Overflow Vulnerability?
A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).
CVE-2026-40130 has been classified to as a Stack Overflow vulnerability or weakness.
Affected Versions
SAP_SE SAPSPrint Service:- Version SAPSPRINT 8.00 is affected.
- Version 8.10 is affected.