---
id: CVE-2026-76971
title: >-
  Due to a Server-Side Request Forgery (SSRF) vulnerability in SAP Manufacturing
  Integration and Intelligence, an attacker could cause the server to initiate
  arbitrary outbound requests
summary: >-
  Due to a Server-Side Request Forgery (SSRF) vulnerability in SAP Manufacturing
  Integration and Intelligence, an attacker could cause the server to initiate
  arbitrary outbound requests. If processed by the application, this behavior
  could…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'
cwe:
  - CWE-918
vendor: SAP_SE
product: SAP Manufacturing Integration and Intelligence
affected:
  - sap_manufacturing_integration_and_intelligence XMII 15.4
  - sap_manufacturing_integration_and_intelligence 15.5
published: '2026-09-08'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T19:12:59.557'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-76971'
references:
  - url: 'https://me.sap.com/notes/3786489'
    label: cna@sap.com
  - url: 'https://url.sap/sapsecuritypatchday'
    label: cna@sap.com
tags:
  - nvd
  - cve.org
epss: 0.00148
epssPercentile: 0.04409
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-08T10:04:46.975263Z'
ingestedAt: '2026-09-08T15:33:26.981Z'
---

## Overview

Due to a Server-Side Request Forgery (SSRF) vulnerability in SAP Manufacturing Integration and Intelligence, an attacker could cause the server to initiate arbitrary outbound requests. If processed by the application, this behavior could be combined with XML/XSL processing to enable execution of scripts. Successful exploitation could result in a low impact on the confidentiality, integrity, and availability of the application.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
