Medium severity5.2NVD Advisory· Published Feb 10, 2026· Updated Jun 17, 2026
CVE-2026-24312
CVE-2026-24312
Description
An erroneous authorization check in SAP Business Workflow leads to privilege escalation. An authenticated administrative user can bypass role restrictions by leveraging permissions from a less sensitive function to execute unauthorized, high-privilege actions. This has a high impact on data integrity, with low impact on confidentiality and no impact on availability of the application.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
10cpe:2.3:a:sap:sap_basis:752:*:*:*:*:*:*:*+ 7 more
- cpe:2.3:a:sap:sap_basis:752:*:*:*:*:*:*:*
- cpe:2.3:a:sap:sap_basis:753:*:*:*:*:*:*:*
- cpe:2.3:a:sap:sap_basis:754:*:*:*:*:*:*:*
- cpe:2.3:a:sap:sap_basis:755:*:*:*:*:*:*:*
- cpe:2.3:a:sap:sap_basis:756:*:*:*:*:*:*:*
- cpe:2.3:a:sap:sap_basis:757:*:*:*:*:*:*:*
- cpe:2.3:a:sap:sap_basis:758:*:*:*:*:*:*:*
- cpe:2.3:a:sap:sap_basis:816:*:*:*:*:*:*:*
SAP_BASIS 752+ 1 more
- (no CPE)range: SAP_BASIS 752
- (no CPE)
Patches
Vulnerability mechanics
References
2- url.sap/sapsecuritypatchdaynvdVendor Advisory
- me.sap.com/notes/3710111nvdPermissions Required
News mentions
0No linked articles in our index yet.