SAP Extended Passport (EPP) Processing vulnerability

A memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing library. Under specific conditions, an unauthenticated attacker could exploit a crafted network request containing a malformed EPP header, potentially resulting in undefined behavior and abnormal program termination. Successful exploitation may have a high impact on the confidentiality, integrity, and availability of the application.

Published 7 Sep 2026Updated 7 Sep 20262 sources
CVSS 10.0

What happened

A memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing library. Under specific conditions, an unauthenticated attacker could exploit a crafted network request containing a malformed EPP header, potentially resulting in undefined behavior and abnormal program termination. Successful exploitation may have a high impact on the confidentiality, integrity, and availability of the application.

Affected versions

SAP Extended Passport (EPP) Processing: KRNL64NUC 7.22; 7.22EXT; KRNL64UC 7.22; 7.53; 8.04; WEBDISP 9.16; 9.18; 9.19; 9.20; KERNEL 7.22; 7.54; 7.77; 7.89; 7.93; 9.16 Fixed: See vendor advisory.

Why it matters

Review the vendor advisory and exposure of the affected product to determine operational impact.

Detection & mitigation

  • Apply vendor-provided updates or mitigations.
  • Review affected product exposure and access logs.

Public PoC references

No public PoC reference has passed the current publication threshold.