An erroneous authorization check in SAP Business Workflow leads to privilege escalation. An authenticated administrative user can bypass role restrictions by leveraging permissions from a less sensitive function to execute unauthorized, high-privilege actions. This has a high impact on data integrity, with low impact on confidentiality and no impact on availability of the application.
References
| Link | Resource |
|---|---|
| https://me.sap.com/notes/3710111 | Permissions Required |
| https://url.sap/sapsecuritypatchday | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-02-10 04:16
Updated : 2026-06-17 10:22
NVD link : CVE-2026-24312
Mitre link : CVE-2026-24312
CVE.ORG link : CVE-2026-24312
JSON object : View
Products Affected
sap
- sap_basis
CWE
CWE-862
Missing Authorization
