Unrated severityNVD Advisory· Published Feb 10, 2026· Updated Feb 10, 2026
Missing authorization check in SAP Business Workflow
CVE-2026-24312
Description
An erroneous authorization check in SAP Business Workflow leads to privilege escalation. An authenticated administrative user can bypass role restrictions by leveraging permissions from a less sensitive function to execute unauthorized, high-privilege actions. This has a high impact on data integrity, with low impact on confidentiality and no impact on availability of the application.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2(expand)+ 1 more
- (no CPE)
- (no CPE)range: SAP_BASIS 752
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.