CVE-2026-44758: Code Injection in SAP Manufacturing Integration and Intelligence
August 12, 2026
A critical code injection vulnerability in SAP Manufacturing Integration and Intelligence (CVSS 9.1) allows an attacker with high privileges to execute arbitrary commands on the underlying OS. The issue involves a servlet component susceptible to SSTI and SSRF, which could lead to command execution. The patch removes the vulnerable servlet.