4 min Security

SAP sounds the alarm about OVERPASS; patch available

SAP sounds the alarm about OVERPASS; patch available

OVERPASS, also known as CVE-2026-44756, is a critical vulnerability within the SAP kernel. Onapsis Research Labs, which discovered the vulnerability, and SAP will provide more details later today about the buffer overflow flaw, which has since been patched.

Attackers who exploit the vulnerability can take control of SAP hosts as unprivileged users. As a result, all process and business data within the SAP instances could potentially be exposed in the event of a compromise, Onapsis concluded after discovering the vulnerability. SAP Communication Manager (ICM) can act as a bridge via HTTP, HTTPS, and SMTP.

10,000 systems, 10.0 score

OVERPASS has been assigned a CVSS score of 10.0. According to Onapsis, patching this vulnerability is an urgent priority. Security Note 3747649 provides a kernel patch that addresses all potential risks. However, it is possible that an attack has already occurred on one of the 10,000 vulnerable SAP systems, even though Onapsis has not detected any. The attacker would therefore have had to discover the vulnerability on their own before security researchers brought it to light.

SAP data can be traced via the so-called Extended Passport (EPP). This is created when a user session starts, before authentication. It uses standard communication protocols and is active by default. Passwords are therefore of no help; only isolated instances that do not provide internet access are practically protected.

Potential consequences

To further emphasize the serious nature of this issue beyond just CVSS scores, the applications of OVERPASS are diverse. According to Onapsis, these include sabotage, espionage, fraud, or violations of regulations such as NIS2, GDPR, or PCI-DSS.

Since this affects the SAP kernel, the very heart of SAP systems is compromised. This means that all versions of SAP S/4HANA, SAP ERP, SAP Business Suite, SAP NetWeaver, and other solutions that use this kernel are vulnerable. It is precisely this widespread use that makes OVERPASS so insidious: it is emphatically not an isolated problem limited to specific tools.

On the hunt for unpatched systems

It is to be expected that some organizations will not patch their SAP systems in a timely manner. But every organization can, of course, prevent itself from falling into that category. First and foremost, a check of the kernel release in use is necessary. Nearly all SAP customers are vulnerable until they apply the patch. It is necessary to identify every SAP system and prioritize instances with internet access. Hardening the connection to the applications can also help as an interim step or additional measure.

This is followed by monitoring for exploitation attempts, something that (as with other critical vulnerabilities) is virtually inevitable.

Mayresh Dani, Security Research Manager at Qualys, noted that “SAP systems run important functions such as finance, payroll, supply chain among others, and typically, a kernel patch needs a system restart – which may be difficult to schedule. Additionally, the vulnerability is reachable three separate ways – the web layer (ICM or Web Dispatcher, i.e. HTTP), the SAP GUI layer, and the RFC layer that links SAP systems to one another. This means that a system that is not exposed to the internet is still exposed via the SAP GUI layer. There is vendor-provided guidance to temporarily mitigate the HTTP attack surface. However, it does not cover the GUI/RFC routes. This translates to mandatory patching of internet-facing systems first, followed by internal systems. This is not optional as the SAP GUI route is open on every application server by design. Organizations can also reduce reachability by making use of SAProuter/jump hosts/Web Dispatcher as hardening measures, and monitor for exploitation during rollout.”

See also: SAP patches vulnerabilities in NetWeaver and Commerce Cloud