CVE-2026-44756
A memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing library. Under specific conditions, an unauthenticated attacker could exploit a crafted network request containing a malformed EPP header, potentially resulting in undefined behavior and abnormal program termination. Successful exploitation may have a high impact on the confidentiality, integrity, and availability of the application.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 10
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- EPSS probability
- 0.32%
- CWE
- CWE-120
- Published
- 2026-09-08
- Last modified
- 2026-09-08
Affected products
- SAP_SE SAP Extended Passport (EPP) Processing
- SAP_SE SAP Extended Passport (EPP) Processing
- SAP_SE SAP Extended Passport (EPP) Processing
- SAP_SE SAP Extended Passport (EPP) Processing
- SAP_SE SAP Extended Passport (EPP) Processing
- SAP_SE SAP Extended Passport (EPP) Processing
- SAP_SE SAP Extended Passport (EPP) Processing
- SAP_SE SAP Extended Passport (EPP) Processing
Weakness type
Related vulnerabilities
- CVE-2026-87931 — Behavioral Technology Group Pavlok Behavioral Conditioning Wearable Apple Notification Center Service Event buffer overflow
- CVE-2026-86166 — Tenda HG10 Boa Web Server formWanRedirect buffer overflow
- CVE-2026-86165 — Tenda HG10 formURL buffer overflow
- CVE-2026-85110 — Tenda HG10 Boa Web Server formWlanSetup buffer overflow
- CVE-2026-85109 — Tenda HG10 Boa Web Server formLogin buffer overflow
- CVE-2026-85031 — TOTOLINK CP450 cstecgi.cgi buffer overflow
- CVE-2026-9625 — RSLinx Classic® - Multiple Vulnerabilities
- CVE-2026-83596 — Webkitgtk: validate the full featurelist array once in opentypeverticaldata findfeature