VYPR
Medium severity4.3NVD Advisory· Published Jan 27, 2026· Updated Apr 15, 2026

CVE-2026-23683

CVE-2026-23683

Description

SAP Fiori App Intercompany Balance Reconciliation does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This has low impact on confidentiality, integrity and availability are not impacted.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

SAP Fiori App Intercompany Balance Reconciliation lacks authorization checks, allowing authenticated users to escalate privileges with limited confidentiality impact.

Vulnerability

Overview

The SAP Fiori App Intercompany Balance Reconciliation fails to enforce proper authorization checks for authenticated users. This missing validation allows a user to access functions or data they are not entitled to, leading to privilege escalation. The vulnerability has a CVSS v3 base score of 4.3 (Medium) and is described as having low impact on confidentiality, with no impact on integrity or availability [1].

Exploitation

Context

An attacker must be authenticated to the SAP system. No special network position or additional privileges are required beyond a valid user account. The weakness lies in the application-level authorization logic, meaning an authenticated user can invoke functions that should require higher privileges [1].

Impact

Assessment

Successful exploitation allows the attacker to gain unauthorized access to certain data or functions within the Intercompany Balance Reconciliation app, resulting in a limited breach of confidentiality. Integrity and availability are not affected [1].

Mitigation

SAP has addressed this vulnerability with the release of a security note as part of its monthly Security Patch Day. Organizations should apply the provided patch or upgrade to the corrected version. No workarounds or out-of-cycle fixes are mentioned [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.