SAP Integration Suite: XXE via XML Entities Exfiltrate Files
CVE-2026-76958 Published on September 8, 2026
XML External Entity (XXE) Vulnerability in SAP Integration Suite
SAP Integration Suite does not sufficiently validate XML documents accepted from untrusted sources in certain internal components. An attacker with low privileges could submit specially crafted XML payloads containing malicious external entity declarations. Successful exploitation could allow the attacker to read sensitive file contents from the server and expose them through monitoring or logging output, resulting in a high impact on confidentiality. It could also lead to resource exhaustion, causing a low impact on availability. There is no impact on integrity.
Vulnerability Analysis
CVE-2026-76958 is exploitable with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality, with no impact on integrity, and a small impact on availability.
Weakness Type
What is a XXE Vulnerability?
The software processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.
CVE-2026-76958 has been classified to as a XXE vulnerability or weakness.
Affected Versions
SAP_SE SAP Integration Suite:- Version Cloud Integration - Trading Partner Management V2 2.9.2 is affected.
- Version B2B Integration Factory - Cloud Integration - Trading Partner Management 1.10.0 is affected.