Description
SAP Manufacturing Integration and Intelligence allows a privileged attacker to exploit insufficient file path validation in certain functions using specially crafted input. Exploitation also requires a legitimate user to subsequently access the attacker-influenced content and depends on conditions outside the attacker�s control. Successful exploitation could allow files to be written outside the intended directory and affect other components, resulting in a high impact on confidentiality, integrity, and availability.
Published: 2026-08-11
Score: 7.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

SAP Manufacturing Integration and Intelligence contains an insufficient file path validation flaw that enables a privileged attacker to create paths that escape the intended working directory. Because the attack requires a legitimate user to subsequently access the attacker‑influenced content, successful exploitation can result in malicious files being written to sensitive locations, potentially corrupting or replacing critical data and impacting downstream systems. The vulnerability is a classic path traversal (CWE‑22).

Affected Systems

This flaw affects installations of SAP Manufacturing Integration and Intelligence, as documented by SAP SE. The vulnerability is specifically present in the versions prior to any patch that addresses the noted file‑path validation issue, though exact version details are not provided.

Risk and Exploitability

The CVSS score of 7.6 indicates a high severity rating. The EPSS score is not available, so the current estimate of exploitation probability is unknown. The vulnerability is not listed in the CISA KEV catalog, suggesting no publicly known exploits. The attack path requires privileged access to the SAP application and subsequent use by a legitimate user; thus, direct remote exploitation is unlikely without a stored, attacker‑controlled file being accessed by a user.

Generated by OpenCVE AI on August 11, 2026 at 01:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the SAP security patch referenced in SAP Note 3759854, which corrects the file path validation flaw.
  • Restrict file upload and write permissions to dedicated directories and verify that directory traversal checks are enforced during all file operations.
  • Ensure that only authorized, least‑privileged accounts have write access to application directories and monitor file system integrity to detect unauthorized modifications.

Generated by OpenCVE AI on August 11, 2026 at 01:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 11 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Sap
Sap manufacturing Integration And Intelligence
Vendors & Products Sap
Sap manufacturing Integration And Intelligence

Tue, 11 Aug 2026 00:45:00 +0000

Type Values Removed Values Added
Description SAP Manufacturing Integration and Intelligence allows a privileged attacker to exploit insufficient file path validation in certain functions using specially crafted input. Exploitation also requires a legitimate user to subsequently access the attacker-influenced content and depends on conditions outside the attacker�s control. Successful exploitation could allow files to be written outside the intended directory and affect other components, resulting in a high impact on confidentiality, integrity, and availability.
Title Directory Traversal vulnerability in SAP Manufacturing Integration and Intelligence
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H'}


Subscriptions

Sap Manufacturing Integration And Intelligence
cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published:

Updated: 2026-08-11T14:32:54.667Z

Reserved: 2026-05-07T18:39:44.146Z

Link: CVE-2026-44763

cve-icon Vulnrichment

Updated: 2026-08-11T14:32:49.880Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-11T01:17:20.930

Modified: 2026-08-26T19:00:14.450

Link: CVE-2026-44763

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-11T14:00:14Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')