Cyber News / Article / A Vulnerability in SAP Extended Passport (EPP) Processing Could Allow for Remote Code Execution

A Vulnerability in SAP Extended Passport (EPP) Processing Could Allow for Remote Code Execution
A vulnerability has been discovered in SAP Extended Passport (EPP) Processing that could allow for remote code execution. SAP Extended Passport (EPP) Processing is a core system data structure and tracing mechanism within SAP Kernel code used to track, log, and monitor end-to-end communication across distributed SAP and non-SAP landscapes. It is created automatically when a new user session opens and travels via communication protocols like RFC (Remote Function Call) and HTTP from the client to the server. Onapsis explained that, because EPP processing is shared kernel code, the vulnerability is reachable from the SAP GUI layer every end user connects to, and from the RFC layer that links SAP systems to one another. The bug is remotely exploitable without authentication and exists by default in a range of SAP components. Successful exploitation of this vulnerability may allow a remote attacker to run arbitrary operating system commands on the SAP host with SAP administrative privileges, leading to a total compromise of the underlying SAP business data and processes.
There are currently no reports of this vulnerability being exploited in the wild.
A vulnerability has been discovered in SAP Extended Passport (EPP) Processing that could allow for remote code execution. Details of the vulnerability are as follows:
Tactic:Initial Access (TA0001)
Technique:Exploit Public-Facing Application (T1190)
Successful exploitation of this vulnerability may allow a remote attacker to run arbitrary operating system commands on the SAP host with SAP administrative privileges, leading to a total compromise of the underlying SAP business data and processes.
We recommend the following actions be taken:
Copyright©2026 Center for Internet Security®
Related articles
Alby Hub Critical Flaw Could Let Attackers Take Over Internet-Exposed Bitcoin Wallets
2 days ago
Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox
2 days ago
New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as Root
2 days ago
You might Also like
Hackers Use Claude AI Agents to Automate Cyberattacks, Develop 0-Days and Evade Detection

New Android malware encrypts files, steals data, and harasses victims

