보안 뉴스 · 업데이트
2026-011: Critical Vulnerabilities in SAP Kernel and NetWeaver Message Server
출처: CERT-EU · © Cybersecurity Service for the Union institutions, bodies, offices and agencies (CERT-EU). · CC BY 4.0
문서 서식과 링크를 FineTS 화면에 맞게 정리했습니다. 이미지·첨부파일은 공식 원문에서 확인하세요.
| 취약점 | 설명 | 조치사항 |
|---|---|---|
| CVE-2026-44756 |
A memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing library. Under specific conditions, an unauthenticated attacker could exploit a crafted network request containing a malformed EPP header, potentially resulting in undefined behavior and abnormal program termination. Successful exploitation may have a high impact on the confidentiality, integrity, and availability of the application. |
조치사항 확인이 필요합니다. |
| CVE-2026-58240 |
SAP NetWeaver Message Server does not sufficiently validate the authenticity of internal application server components during registration. An unauthenticated attacker with network access to the affected service could exploit this weakness to register an unauthorized component and potentially perform unauthorized actions within the application environment, resulting in a high impact on the confidentiality, integrity, and availability of the affected system. |
조치사항 확인이 필요합니다. |
자동 한국어 번역
영문 원문을 FineTS가 한국어로 자동 번역한 내용입니다. 번역 과정에서 표현 차이나 오류가 있을 수 있습니다.
번역 시각: 2026. 09. 14. 21:59 KST · 기준 원문 수집: 2026. 09. 12. 18:31 KST
8 9 월 2026, 9 월 보안 패치의 일부로서 SAP는 SAP 제품의 광범위한 영향을 미치는 2 치명적 취약점의 보안 노트를 발표했습니다 [3]. 가장 심한 CVE-2026-44756 (CVSS 10.0)는 SAP Extended Passport (EPP) Processin의 메모리 손상 취약점입니다
역사:
- 09/09/2026 --- v1.0 -- 처음 발행.
개요
8 9 월 2026, 9 월 보안 패치의 일부로서 SAP는 SAP 제품의 광범위한 영향을 미치는 2 치명적 취약점의 보안 노트를 발표했습니다 [1][3]. 가장 심한 CVE-2026-44756 (CVSS 10.0)은 SAP Extended Passport (EPP) 처리의 메모리 손상 취약점입니다. Onapsis Research Labs (ORL)에 의해 "OVERPASS"라는 별칭 된 "OVERPASS"는 발견하고 책임을 공개했습니다 [2][3]. 두 번째, CVE-2026-58240 (CVSS 9.8), 별명 "S4GET"은 SAP NetWeaver 메시지 서버에서 누락 된 인증 검사입니다 [3][6].
둘 다 인증 없이 멀게 적용 가능합니다. 보고 연구원에 따르면, 성공적인 악용 중 하나는 SAP 설치를 소유하고있는 계정의 임의 운영 체제 명령 실행에서 결과 할 수 있으며 영향을받는 시스템의 전체 타협과 비즈니스 데이터가 보유합니다 [2][6].
CERT-EU는 다음 작업을 권장합니다. 가능한 한 빨리 SAP Security Notes 3747649 및 3759472에 기술된 업데이트를 설치해야 합니다 [1].
기술 상세
CVE-2026-44756 - "OVERPASS"(CVSS 10.0)
CVE-2026-44756는 SAP Security Note 3747649에 의해 해결되는 확장 여권 (EPP)을 처리하는 SAP Kernel 라이브러리의 메모리 손상 취약점입니다 [1][4]. SAP의 CVE 레코드는 경계 검증이 EPP 데이터의 탈중앙화 중에 누락되고, 인증되지 않은 공격자는 변형된 EPP 헤더를 포함하는 만들어진 네트워크 요청을 보낼 수 있으며, 잠재적으로 비정상적인 행동과 비정상적인 프로그램 종료 결과, 기밀성, 무결성 및 가용성에 대한 높은 영향으로 [2][3].
취약점을 보고한 Onapsis는 악용가 SAP 관리 권한을 가진 SAP 호스트의 임의 운영 체제 명령을 실행하기 위해 원격 공격자을 허용하는 것으로 평가합니다. SAP 비즈니스 데이터 및 프로세스의 전체 손상으로 결과 [2].
CVE-2026-58240 - "S4GET"(CVSS 9.8)
CVE-2026-58240은 SAP NetWeaver Message Server (component BC-CST-MS)의 누락된 인증 체크로서 SAP Security Note 3759472에 의해 해결됩니다 [1][5]. Message Server는 등록시 내부 애플리케이션 서버 구성 요소를 충분히 유효하지 않습니다. 따라서 네트워크 액세스와 인증되지 않은 공격자는 허가되지 않은 구성 요소를 등록하고 잠재적으로 애플리케이션 환경에서 허가되지 않은 작업을 수행 할 수 있으며, 영향을받는 시스템의 기밀성, 무결성 및 가용성에 대한 높은 영향으로 결과 [3][5].
또한이 취약점을보고 한 Onapsis는 공격자가 SAP 클러스터 내부의 신뢰할 수있는 노드로 스스로 홍보 할 수 있다고 주장하는 메시지 서버는 클러스터의 모든 응용 서버에 신뢰하고 성공적인 공격은 SAP를 실행하는 운영 체제 사용자로서 원격 코드 실행을 산출합니다 [6]. Onapsis 노트는 SAP GUI 클라이언트가 연결되는 동일한 공공 포트를 통해 결함이 도달 할 수 있으므로 최종 사용자 로고를 깨지 않고 방화벽이 될 수 없습니다 [6].
영향받는 제품
CVE-2026-44756 -- 영향을받는 버전 [1]:
- KRNL64NUC 7.22, 7.22EXT
- KRNL64UC 7.22, 7.22EXT, 7.53, 8.04
- KERNEL 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 8.04, 9.16, 9.18, 9.19, 9.20
- WEBDISP 9.16, 9.18, 9.19, 9.20
CVE-2026-58240 -- 영향을받는 버전 [1]:
- KERNEL 9.16, 9.18, 9.19, 9.20
권고 사항
CERT-EU는 다음 작업을 권장합니다. SAP Security Note 3747649 (CVE-2026-44756) 및 SAP Security Note 3759472 (CVE-2026-58240)를 따라 즉시 관련 버전에 영향을 미치는 제품을 업데이트해야합니다 [1].
참고 자료
[1] https://support.sap.com/en/my-support/knowledge-base/security-notes-news/september-2026.html
[2] https://onapsis.com/blog/sap-overpass-remediation/
[3] https://onapsis.com/blog/sap-security-patch-day-september-2026/
[4] https://www.cve.org/CVERecord?id=CVE-2026-44756
[5] https://www.cve.org/CVERecord?id=CVE-2026-58240
[6] https://onapsis.com/blog/s4get-cve-2026-58240-sap-message-server-threat-advisory/
On 8 September 2026, as part of its September Security Patch Day, SAP released Security Notes addressing two critical vulnerabilities affecting a broad range of SAP products[3]. The most severe, CVE-2026-44756 (CVSS 10.0), is a memory corruption vulnerability in SAP Extended Passport (EPP) processin
History:
- 09/09/2026 --- v1.0 -- Initial publication.
Summary
On 8 September 2026, as part of its September Security Patch Day, SAP released Security Notes addressing two critical vulnerabilities affecting a broad range of SAP products [1][3]. The most severe, CVE-2026-44756 (CVSS 10.0), is a memory corruption vulnerability in SAP Extended Passport (EPP) processing, nicknamed "OVERPASS" by the Onapsis Research Labs (ORL), which discovered and responsibly disclosed it [2][3]. The second, CVE-2026-58240 (CVSS 9.8), nicknamed "S4GET", is a missing authentication check in the SAP NetWeaver Message Server [3][6].
Both are remotely exploitable without authentication. According to the reporting researchers, successful exploitation of either can result in arbitrary operating system command execution under the account that owns the SAP installation, leading to full compromise of the affected system and the business data it holds [2][6].
CERT-EU strongly recommends applying SAP Security Notes 3747649 and 3759472 as soon as possible [1].
Technical Details
CVE-2026-44756 - "OVERPASS" (CVSS 10.0)
CVE-2026-44756 is a memory corruption vulnerability in the SAP Kernel library that processes the Extended Passport (EPP), addressed by SAP Security Note 3747649 [1][4]. SAP's CVE record states that boundary validation is missing during the deserialisation of EPP data, and that an unauthenticated attacker can send a crafted network request containing a malformed EPP header, potentially resulting in undefined behaviour and abnormal program termination, with a high impact on confidentiality, integrity, and availability [2][3].
Onapsis, which reported the vulnerability, assesses that successful exploitation allows a remote attacker to execute arbitrary operating system commands on the SAP host with SAP administrative privileges, resulting in full compromise of the underlying SAP business data and processes [2].
CVE-2026-58240 - "S4GET" (CVSS 9.8)
CVE-2026-58240 is a missing authentication check in the SAP NetWeaver Message Server (component BC-CST-MS), addressed by SAP Security Note 3759472 [1][5]. The Message Server does not sufficiently validate the authenticity of internal application server components during registration. Consequently, an unauthenticated attacker with network access can register unauthorised components and potentially perform unauthorised actions within the application environment, resulting in a high impact on the confidentiality, integrity, and availability of the affected system [3][5].
Onapsis, which also reported this vulnerability, states that an attacker can promote themselves to a trusted node inside an SAP cluster, that the Message Server propagates that trust to every application server in the cluster, and that a successful attack yields remote code execution as the operating-system user that runs SAP [6]. Onapsis notes the flaw is reachable through the same public port that SAP GUI clients connect to, which cannot be firewalled without breaking end-user logon [6].
Affected Products
CVE-2026-44756 -- affected versions [1]:
- KRNL64NUC 7.22, 7.22EXT
- KRNL64UC 7.22, 7.22EXT, 7.53, 8.04
- KERNEL 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 8.04, 9.16, 9.18, 9.19, 9.20
- WEBDISP 9.16, 9.18, 9.19, 9.20
CVE-2026-58240 -- affected versions [1]:
- KERNEL 9.16, 9.18, 9.19, 9.20
Recommendations
CERT-EU strongly recommends following SAP Security Note 3747649 (CVE-2026-44756) and SAP Security Note 3759472 (CVE-2026-58240) to update the affected products to the relevant versions as soon as possible [1].
References
[1] https://support.sap.com/en/my-support/knowledge-base/security-notes-news/september-2026.html
[2] https://onapsis.com/blog/sap-overpass-remediation/
[3] https://onapsis.com/blog/sap-security-patch-day-september-2026/
[4] https://www.cve.org/CVERecord?id=CVE-2026-44756
[5] https://www.cve.org/CVERecord?id=CVE-2026-58240
[6] https://onapsis.com/blog/s4get-cve-2026-58240-sap-message-server-threat-advisory/