Skip to content
tag — onapsis

grep -rl "onapsis" ./articles

#onapsis

1 article

The SAP flaw runs before authentication, so Segregation of Duties does not apply

2026-09-09Security

CVE-2026-44756 is a CVSS 10.0 memory corruption bug in the SAP kernel's Extended Passport handling, reachable with a single malformed header. Onapsis puts the consequence plainly: SAP authorizations and Segregation of Duties will not help, because the vulnerable code runs before any authentication step.