Advisory
A note with CVSS 5.3 for component BC-CCM-PRN was released by SAP on 11.08.2026. The correction/advisory 3725940 was described with "3725940 - [CVE-2026-40130] Memory Corruption vulnerability in SAPSPrint Service" and affects the system type SAPSprint.
A workaround does not exist, according to SAP Security Advisory team. It is advisable to implement the correction as monthly patch process.
The vulnerability addressed is memory corruption within SAPSprint.
Risk specification
SAP SAPSPrint Service allows an unauthenticated attacker to send specially crafted requests that trigger a buffer overflow, resulting in a temporary service interruption and automatic restart.
Solution
The affected component has been hardened so that specially crafted input can no longer be misused to compromise the system.
