CVE-2025-26656
Description
The OData Service in SAP Manage Purchasing Info Records lacks authorization checks, allowing authenticated users to escalate privileges with low integrity impact.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
The OData Service in SAP Manage Purchasing Info Records lacks authorization checks, allowing authenticated users to escalate privileges with low integrity impact.
Vulnerability
Overview
The OData Service in SAP Manage Purchasing Info Records fails to perform necessary authorization checks for authenticated users. This missing access control allows an authenticated user to perform actions that should be restricted, leading to privilege escalation within the application. The root cause is the absence of proper authorization validation in the OData service endpoint.
Exploitation
Prerequisites
An attacker must be authenticated to the SAP system. No special network position is required beyond normal access to the SAP application. The attacker can send crafted OData requests to the vulnerable service to bypass intended access controls and escalate their privileges.
Impact
The vulnerability has a low impact on integrity, as per the CVSS v3 score of 4.3 (Medium). An attacker could potentially modify purchasing info records or related data, but the confidentiality and availability of the system are not affected. The privilege escalation is limited to the scope of the Manage Purchasing Info Records functionality.
Mitigation
SAP has released a security note addressing this vulnerability as part of its regular Security Patch Day [1]. Administrators should apply the relevant patch to remediate the issue. The reference provides general guidance on SAP security maintenance and patch deployment [1].
AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.