VYPR
Medium severity4.3NVD Advisory· Published Mar 11, 2025· Updated Apr 15, 2026

CVE-2025-26656

CVE-2025-26656

Description

The OData Service in SAP Manage Purchasing Info Records lacks authorization checks, allowing authenticated users to escalate privileges with low integrity impact.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

The OData Service in SAP Manage Purchasing Info Records lacks authorization checks, allowing authenticated users to escalate privileges with low integrity impact.

Vulnerability

Overview

The OData Service in SAP Manage Purchasing Info Records fails to perform necessary authorization checks for authenticated users. This missing access control allows an authenticated user to perform actions that should be restricted, leading to privilege escalation within the application. The root cause is the absence of proper authorization validation in the OData service endpoint.

Exploitation

Prerequisites

An attacker must be authenticated to the SAP system. No special network position is required beyond normal access to the SAP application. The attacker can send crafted OData requests to the vulnerable service to bypass intended access controls and escalate their privileges.

Impact

The vulnerability has a low impact on integrity, as per the CVSS v3 score of 4.3 (Medium). An attacker could potentially modify purchasing info records or related data, but the confidentiality and availability of the system are not affected. The privilege escalation is limited to the scope of the Manage Purchasing Info Records functionality.

Mitigation

SAP has released a security note addressing this vulnerability as part of its regular Security Patch Day [1]. Administrators should apply the relevant patch to remediate the issue. The reference provides general guidance on SAP security maintenance and patch deployment [1].

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.