SAP MII Cost Servlet Missing Auth Enables Data Modification
CVE-2026-44764 Published on August 11, 2026

Missing Authorization Check in SAP Manufacturing Integration and Intelligence
Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence, an unauthenticated attacker could send crafted requests to the Cost Servlet using specific parameter values. If processed by the application, these requests enable access to backend operations. Successful exploitation could allow the attacker to read, create, modify, or delete application-managed business data, resulting in a limited impact on the confidentiality, integrity, and availability of the affected system.

NVD

Vulnerability Analysis

CVE-2026-44764 is exploitable with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to be low. considered to have a small impact on confidentiality and integrity and availability.

Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
LOW
Integrity Impact:
LOW
Availability Impact:
LOW

Weakness Type

What is an AuthZ Vulnerability?

The software does not perform an authorization check when an actor attempts to access a resource or perform an action.

CVE-2026-44764 has been classified to as an AuthZ vulnerability or weakness.


Products Associated with CVE-2026-44764

Want to know whenever a new CVE is published for SAP Manufacturing Integration Intelligence? stack.watch will email you.

 

Affected Versions

SAP_SE SAP Manufacturing Integration and Intelligence: