← Back

CVE-2026-24312

nvd nist
Published: Feb 10, 2026Modified: Jun 17, 2026

JSON object

Loading...
5.2
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:H/A:N
Exploitability: 0.9 / Impact: 4.2
Source: NVD

Description

An erroneous authorization check in SAP Business Workflow leads to privilege escalation. An authenticated administrative user can bypass role restrictions by leveraging permissions from a less sensitive function to execute unauthorized, high-privilege actions. This has a high impact on data integrity, with low impact on confidentiality and no impact on availability of the application.

Affected (8)

Products: Sap: Sap Basis
1 product
Sap Basis
Configuration A
8 vulnerable
Vulnerable SoftwareAffected Versions
Sap
Version 752
Version 753
Version 754
Version 755
Version 756
Version 757
Version 758
Version 816

References (2)

Source: cna@sap.com
Permissions Required
Source: cna@sap.com
Vendor Advisory

Timeline

No history available yet.