SAP Note 3765948: Code Injection via SSRF in SAP MII (CVE-2026-44772)
CVE-2026-44772, CVSS 9.9: XSL transform parameters let an authenticated user make SAP MII fetch and execute a remote stylesheet. The gate ships disabled.
Co-founder and CTO of RedRays
CVE-2026-44772, CVSS 9.9: XSL transform parameters let an authenticated user make SAP MII fetch and execute a remote stylesheet. The gate ships disabled.
CVE-2026-44758, CVSS 9.1: the SAP MII IllumXSLTServlet compiled a caller supplied stylesheet. SAP removed the endpoint rather than patching it.
CVE-2026-44763, CVSS 7.6: a save path in the SAP MII SSCE interface was assembled without containment, letting files land outside the intended folder.
CVE-2026-44765, CVSS 7.3: SAP MII scheduling functions were reachable without an authorization check. The fix adds guards and new role assignments.
Adding {{itemName}} to cart
Added {{itemName}} to cart