---
id: CVE-2026-44756
title: >-
  A memory safety vulnerability exists in the Extended Passport Protocol (EPP)
  processing library
summary: >-
  A memory safety vulnerability exists in the Extended Passport Protocol (EPP)
  processing library. Under specific conditions, an unauthenticated attacker
  could exploit a crafted network request containing a malformed EPP header,
  potentiall…
severity: critical
cvss: 10
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'
cwe:
  - CWE-120
vendor: SAP_SE
product: SAP Extended Passport (EPP) Processing
affected:
  - sap_extended_passport_epp_processing KRNL64NUC 7.22
  - sap_extended_passport_epp_processing 7.22EXT
  - sap_extended_passport_epp_processing KRNL64UC 7.22
  - sap_extended_passport_epp_processing 7.53
  - sap_extended_passport_epp_processing 8.04
  - sap_extended_passport_epp_processing WEBDISP 9.16
  - sap_extended_passport_epp_processing 9.18
  - sap_extended_passport_epp_processing 9.19
  - sap_extended_passport_epp_processing 9.20
  - sap_extended_passport_epp_processing KERNEL 7.22
  - sap_extended_passport_epp_processing 7.54
  - sap_extended_passport_epp_processing 7.77
  - sap_extended_passport_epp_processing 7.89
  - sap_extended_passport_epp_processing 7.93
  - sap_extended_passport_epp_processing 9.16
published: '2026-09-08'
updated: '2026-09-22'
sourceUpdated: '2026-09-22T21:17:30.593'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-44756'
references:
  - url: 'https://me.sap.com/notes/3747649'
    label: cna@sap.com
  - url: 'https://url.sap/sapsecuritypatchday'
    label: cna@sap.com
  - url: 'http://seclists.org/fulldisclosure/2026/Sep/65'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - cve.org
epss: 0.00678
epssPercentile: 0.50275
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-09-08T12:42:08.435607Z'
ingestedAt: '2026-09-08T15:33:26.981Z'
---

## Overview

A memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing library. Under specific conditions, an unauthenticated attacker could exploit a crafted network request containing a malformed EPP header, potentially resulting in undefined behavior and abnormal program termination. Successful exploitation may have a high impact on the confidentiality, integrity, and availability of the application.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
