CVE-2026-24312
Undergoing Analysis Undergoing Analysis - In Progress
Authorization Bypass in SAP Business Workflow Enables Privilege Escalation

Publication date: 2026-02-10

Last updated on: 2026-02-17

Assigner: SAP SE

Description
An erroneous authorization check in SAP Business Workflow leads to privilege escalation. An authenticated administrative user can bypass role restrictions by leveraging permissions from a less sensitive function to execute unauthorized, high-privilege actions. This has a high impact on data integrity, with low impact on confidentiality and no impact on availability of the application.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-02-10
Last Modified
2026-02-17
Generated
2026-06-16
AI Q&A
2026-02-10
EPSS Evaluated
2026-06-14
NVD
EUVD
Affected Vendors & Products
Showing 8 associated CPEs
Vendor Product Version / Range
sap sap_basis 752
sap sap_basis 753
sap sap_basis 754
sap sap_basis 755
sap sap_basis 756
sap sap_basis 757
sap sap_basis 758
sap sap_basis 816
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability is an erroneous authorization check in SAP Business Workflow that allows privilege escalation. Specifically, an authenticated administrative user can bypass role restrictions by using permissions from a less sensitive function to perform unauthorized, high-privilege actions.

Impact Analysis

The vulnerability has a high impact on data integrity because unauthorized high-privilege actions can be executed. It has a low impact on confidentiality and no impact on the availability of the application.

Compliance Impact

I don't know

Detection Guidance

I don't know

Mitigation Strategies

I don't know

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-24312. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart