---
id: CVE-2026-76958
title: >-
  SAP Integration Suite does not sufficiently validate XML documents accepted
  from untrusted sources in certain internal components
summary: >-
  SAP Integration Suite does not sufficiently validate XML documents accepted
  from untrusted sources in certain internal components. An attacker with low
  privileges could submit specially crafted XML payloads containing malicious
  external …
severity: high
cvss: 8.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L'
cwe:
  - CWE-611
vendor: SAP_SE
product: SAP Integration Suite
affected:
  - >-
    sap_integration_suite Cloud Integration - Trading Partner Management V2
    2.9.2
  - >-
    sap_integration_suite B2B Integration Factory - Cloud Integration - Trading
    Partner Management 1.10.0
published: '2026-09-08'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T19:12:59.557'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-76958'
references:
  - url: 'https://me.sap.com/notes/3792978'
    label: cna@sap.com
  - url: 'https://url.sap/sapsecuritypatchday'
    label: cna@sap.com
tags:
  - nvd
  - cve.org
epss: 0.00223
epssPercentile: 0.13211
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-08T10:01:35.590591Z'
ingestedAt: '2026-09-08T15:33:26.981Z'
---

## Overview

SAP Integration Suite does not sufficiently validate XML documents accepted from untrusted sources in certain internal components. An attacker with low privileges could submit specially crafted XML payloads containing malicious external entity declarations. Successful exploitation could allow the attacker to read sensitive file contents from the server and expose them through monitoring or logging output, resulting in a high impact on confidentiality. It could also lead to resource exhaustion, causing a low impact on availability. There is no impact on integrity.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
