CVE 5.2 MEDIUM

Missing authorization check in SAP Business Workflow_CVE-2026-24312

5.2 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:H/A:N

Description

An erroneous authorization check in SAP Business Workflow leads to privilege escalation. An authenticated administrative user can bypass role restrictions by leveraging permissions from a less sensitive function to execute unauthorized, high-privilege actions. This has a high impact on data integrity, with low impact on confidentiality and no impact on availability of the application.

Basic Information

ID CVE-2026-24312
Source sap
Published Feb 10, 2026 at 03:03

Affected Product

Vendor SAP_SE
Product SAP Business Workflow
Version SAP_BASIS 752
Affected Versions SAP_SE SAP Business Workflow SAP_BASIS 752
SAP_SE SAP Business Workflow SAP_BASIS 753
SAP_SE SAP Business Workflow SAP_BASIS 754
SAP_SE SAP Business Workflow SAP_BASIS 755
SAP_SE SAP Business Workflow SAP_BASIS 756
SAP_SE SAP Business Workflow SAP_BASIS 757
SAP_SE SAP Business Workflow SAP_BASIS 758
SAP_SE SAP Business Workflow SAP_BASIS 816

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.