SAP Patches Critical Flaw That Let Attackers Run Commands on Your Business Software Without a Password
A serious vulnerability in SAP's widely used business software could have let criminals break in, steal sensitive data, and alter records, all without needing a single login credential.

Key points
- SAP patched a critical vulnerability in its kernel code that allowed unauthenticated remote attackers to run arbitrary commands on affected systems.
- The flaw affected SAP's Extended Passport processing component, a piece of technology used across SAP's enterprise software products.
- Attackers could exploit the bug to steal secrets and modify data without supplying a username or password.
- SAP has released a fix, and organisations running affected versions should apply the patch immediately.
SAP, the German software giant whose products power payroll, finance, and supply-chain operations at tens of thousands of companies worldwide, has patched a critical security flaw. First reported by SecurityWeek, the vulnerability sat inside SAP's kernel code, which is the deep, foundational layer that everything else in the software depends on.
The bug lived in a component called Extended Passport processing. An Extended Passport, in SAP's world, is not a travel document: it is a digital token that SAP applications use to pass identity information between different parts of the software. When the code that handled those tokens contained a flaw, it opened a very wide door.
What could an attacker actually do?
Almost anything. An unauthenticated attacker, meaning someone who had not logged in and had no valid account at all, could send a specially crafted request to a vulnerable SAP system over the internet and immediately gain the ability to run arbitrary commands. "Arbitrary commands" means the attacker could instruct the server to do whatever they liked: copy out sensitive data, change financial records, plant malicious software, or disable the system entirely.
They could also recover secrets stored in the system, such as passwords, encryption keys, or API credentials (the private codes that allow different software services to talk to each other). With those in hand, further attacks on connected systems become straightforward.
No phishing email. No stolen password. No insider access. Just a network connection and knowledge of the flaw.
Should customers be worried?
If your organisation uses SAP and has already applied the patch, the immediate risk is gone. If it has not, the risk is serious.
SAP software typically holds some of the most sensitive data a company owns: employee records, payroll figures, banking details, supplier contracts. A successful exploit here could feed a ransomware attack (where criminals lock your files until you pay), a financial fraud, or a quiet, long-term data theft that goes unnoticed for months.
Ordinarily, I note whether multi-factor authentication (MFA), which requires a second proof of identity beyond a password, would have helped. Here it would not have mattered. The flaw bypassed login entirely. Patching is the only real fix.
| Detail | Specifics |
|---|---|
| Vendor | SAP |
| Component affected | Extended Passport processing (SAP kernel) |
| Attack type | Remote, unauthenticated command execution |
| Data at risk | Secrets, stored credentials, business records |
| Fix available | Yes, patch released by SAP |
If you work at an organisation that runs SAP, the most useful thing you can do today is ask your IT or security team whether the patch has been applied. That is a one-question conversation with a concrete answer.



