CVE-2026-76971

MEDIUM CVSS 3.1: 6.5 EPSS 0.15%
Updated Sep 08, 2026
SAP
Parameter Value
CVSS 6.5 (MEDIUM)
Type CWE-918 (Server-Side Request Forgery (SSRF))
Vendor SAP
Public PoC No

Due to a Server-Side Request Forgery (SSRF) vulnerability in SAP Manufacturing Integration and Intelligence, an attacker could cause the server to initiate arbitrary outbound requests. If processed by the application, this behavior could be combined with XML/XSL processing to enable execution of scripts. Successful exploitation could result in a low impact on the confidentiality, integrity, and availability of the application.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
Low
Basic privileges needed
User Interaction
Required
User action required

Impact Assessment

Confidentiality
Low
Partial data leak
Integrity
Low
Partial data modification
Availability
Low
Partial disruption

CVSS Vector v3.1