HomeSapCVE-2026-24312

CVE-2026-24312

MEDIUM
5.2CVSS
Published: 2026-02-10
Updated: 2026-02-17
AI Analysis

Description

An erroneous authorization check in SAP Business Workflow leads to privilege escalation. An authenticated administrative user can bypass role restrictions by leveraging permissions from a less sensitive function to execute unauthorized, high-privilege actions. This has a high impact on data integrity, with low impact on confidentiality and no impact on availability of the application.

CVSS Metrics

Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:H/A:N
Attack Vector
network
Complexity
low
Privileges
high
User Action
required
Scope
unchanged
Confidentiality
low
Integrity
high
Availability
none
Weaknesses
CWE-862

Metadata

Primary Vendor
SAP
Published
2/10/2026
Last Modified
2/17/2026
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

sap : sap_basissap : sap_basissap : sap_basissap : sap_basissap : sap_basissap : sap_basissap : sap_basissap : sap_basis

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief