CVE-2026-23683
Privilege Escalation in SAP Fiori Intercompany Balance App
Publication date: 2026-01-27
Last updated on: 2026-01-27
Assigner: SAP SE
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| sap | fiori_app_intercompany_balance_reconciliation | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-862 | The product does not perform an authorization check when an actor attempts to access a resource or perform an action. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability exists in the SAP Fiori App Intercompany Balance Reconciliation where the application does not perform the necessary authorization checks for an authenticated user. This flaw allows an authenticated user to escalate their privileges beyond what they should normally have. [1]
How can this vulnerability impact me? :
The vulnerability can lead to escalation of privileges for an authenticated user, potentially allowing them to access or perform actions they are not authorized to. However, it has low impact on confidentiality and does not affect integrity or availability. [1]