Unrated severityNVD Advisory· Published Feb 10, 2026· Updated Feb 10, 2026
Missing authorization check in SAP Business Workflow
CVE-2026-24312
Description
An erroneous authorization check in SAP Business Workflow leads to privilege escalation. An authenticated administrative user can bypass role restrictions by leveraging permissions from a less sensitive function to execute unauthorized, high-privilege actions. This has a high impact on data integrity, with low impact on confidentiality and no impact on availability of the application.
Affected products
2- SAP_SE/SAP Business Workflowv5Range: SAP_BASIS 752
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.