VYPR
Medium severity5.2NVD Advisory· Published Feb 10, 2026· Updated Jun 17, 2026

CVE-2026-24312

CVE-2026-24312

Description

An erroneous authorization check in SAP Business Workflow leads to privilege escalation. An authenticated administrative user can bypass role restrictions by leveraging permissions from a less sensitive function to execute unauthorized, high-privilege actions. This has a high impact on data integrity, with low impact on confidentiality and no impact on availability of the application.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

10
  • SAP/BASIS8 versions
    cpe:2.3:a:sap:sap_basis:752:*:*:*:*:*:*:*+ 7 more
    • cpe:2.3:a:sap:sap_basis:752:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:sap_basis:753:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:sap_basis:754:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:sap_basis:755:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:sap_basis:756:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:sap_basis:757:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:sap_basis:758:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:sap_basis:816:*:*:*:*:*:*:*
  • SAP/Business Workflowcpe-rescue2 versions
    SAP_BASIS 752+ 1 more
    • (no CPE)range: SAP_BASIS 752
    • (no CPE)

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.