critical2026-08-11SAP Manufacturing Integration and IntelligenceCVE-2026-44758

Code Injection via XSL Transformation Servlet (IllumXSLTServlet) in SAP MII

SAP Manufacturing Integration and Intelligence (MII)

Our Take

Two critical code injection notes in MII in a single month (plus four more MII notes at lower severities) makes MII the product of the month for all the wrong reasons. Apply Notes 3765948 and 3758900 together in a single MII maintenance window.

Vulnerability Detail

A second code injection vulnerability in SAP Manufacturing Integration and Intelligence affects the IllumXSLTServlet component, which was susceptible to server-side template injection (SSTI). A highly privileged attacker can supply a malicious XSL template that causes the servlet to execute arbitrary operating system commands on the MII host. SAP removed the vulnerable servlet as part of the remediation.

Workaround

Restrict access to the IllumXSLTServlet endpoint via WAF or application-level controls as a temporary measure.

Patch Action

Apply SAP Note 3758900. Bundle with Note 3765948 — both address MII code injection and affect the same versions.

Affected Versions

SAP MII 15.4
15.5

Patch Info

Priority

🔴 Patch immediately

CVSS Score

9.1

SAP Note

3758900

CVE

CVE-2026-44758

Published

2026-08-11

← All patches