VYPR
Medium severity4.3NVD Advisory· Published Jan 13, 2026· Updated Apr 15, 2026

CVE-2026-0497

CVE-2026-0497

Description

SAP Product Designer Web UI of Business Server Pages allows authenticated non-administrative users to access non-sensitive information. This results in a low impact on confidentiality, with no impact on integrity or availability of the application.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

SAP Product Designer Web UI allows authenticated non-administrative users to access non-sensitive information, with low confidentiality impact.

Vulnerability

Overview

CVE-2026-0497 affects the SAP Product Designer Web UI component of Business Server Pages (BSP). The vulnerability allows authenticated users who do not hold administrative privileges to access non-sensitive information that should otherwise be restricted. The root cause lies in insufficient access control checks within the Web UI, enabling a low-severity information disclosure [1].

Exploitation

Prerequisites

An attacker must first obtain valid authentication credentials for a non-administrative user account on the SAP system. No special network position or additional privileges are required beyond standard user access. The attack vector is over the network, and the complexity is low, as the vulnerability can be triggered through normal web requests to the affected UI component [1].

Impact

Successful exploitation results in the disclosure of non-sensitive information, which may include configuration details or metadata that could aid in further reconnaissance. The CVSS v3 base score of 4.3 (Medium) reflects a low impact on confidentiality, with no impact on integrity or availability [1].

Mitigation

SAP has released a security note as part of its regular Patch Day cycle. Administrators should apply the provided patch to correct the access control flaw. No workarounds have been published, and the vulnerability is not known to be exploited in the wild [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.