Skip to content
tag — erp

grep -rl "erp" ./articles

#erp

1 article

The SAP flaw runs before authentication, so Segregation of Duties does not apply

2026-09-09Security

CVE-2026-44756 is a CVSS 10.0 memory corruption bug in the SAP kernel's Extended Passport handling, reachable with a single malformed header. Onapsis puts the consequence plainly: SAP authorizations and Segregation of Duties will not help, because the vulnerable code runs before any authentication step.