CVE 4.3 MEDIUM

Missing authorization check in SAP S/4HANA Defense & Security (Disconnected Operations)_CVE-2026-24326

4.3 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Description

Due to a missing authorization check in the Disconnected Operations of the SAP S/4HANA Defense & Security, an attacker with user privileges could call remote-enabled function modules to do direct update on standard SAP database table . This results in low impact on integrity, with no impact on confidentiality or availability of the application.

Basic Information

ID CVE-2026-24326
Source sap
Published Feb 10, 2026 at 03:04

Affected Product

Vendor SAP_SE
Product SAP S/4HANA Defense & Security (Disconnected Operations)
Version EA-DFPS 600
Affected Versions SAP_SE SAP S/4HANA Defense & Security (Disconnected Operations) EA-DFPS 600
SAP_SE SAP S/4HANA Defense & Security (Disconnected Operations) 603
SAP_SE SAP S/4HANA Defense & Security (Disconnected Operations) 604
SAP_SE SAP S/4HANA Defense & Security (Disconnected Operations) 605
SAP_SE SAP S/4HANA Defense & Security (Disconnected Operations) 606
SAP_SE SAP S/4HANA Defense & Security (Disconnected Operations) 616
SAP_SE SAP S/4HANA Defense & Security (Disconnected Operations) 617
SAP_SE SAP S/4HANA Defense & Security (Disconnected Operations) 618
SAP_SE SAP S/4HANA Defense & Security (Disconnected Operations) 619
SAP_SE SAP S/4HANA Defense & Security (Disconnected Operations) 800
SAP_SE SAP S/4HANA Defense & Security (Disconnected Operations) 801
SAP_SE SAP S/4HANA Defense & Security (Disconnected Operations) 802
SAP_SE SAP S/4HANA Defense & Security (Disconnected Operations) 803
SAP_SE SAP S/4HANA Defense & Security (Disconnected Operations) 804
SAP_SE SAP S/4HANA Defense & Security (Disconnected Operations) 805
SAP_SE SAP S/4HANA Defense & Security (Disconnected Operations) 806
SAP_SE SAP S/4HANA Defense & Security (Disconnected Operations) 807
SAP_SE SAP S/4HANA Defense & Security (Disconnected Operations) 808
SAP_SE SAP S/4HANA Defense & Security (Disconnected Operations) 809

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.