CVE-2026-58244
Received Received - Intake

Authorization Bypass in SAP MII Exposes User Data

Vulnerability report for CVE-2026-58244, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-11

Last updated on: 2026-08-11

Assigner: SAP SE

Description

SAP Manufacturing Integration and Intelligence (MII) does not perform necessary authorization check on certain application function, allowing a low-privileged authenticated attacker to access information that should be restricted to privileged users. Successful exploitation could allow the attacker to access the users account information in the application, which could be leveraged to facilitate further attacks against the identified user accounts. This vulnerability results in low impact on confidentiality of the data, with no impact on the integrity and availability

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-11
Last Modified
2026-08-11
Generated
2026-08-11
AI Q&A
2026-08-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
sap manufacturing_integration_and_intelligence *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

SAP Manufacturing Integration and Intelligence (MII) fails to properly check user permissions for certain functions. A low-privileged attacker with valid login credentials can access restricted information meant only for higher-privileged users. This could let them view sensitive account details of other users, which might be used for additional attacks.

Detection Guidance

This vulnerability involves insufficient authorization checks in SAP MII. To detect it, review SAP MII application logs for unauthorized access attempts to restricted user account information. Check for unusual data retrieval patterns or requests to sensitive endpoints by low-privileged users. No specific commands are provided in the context.

Impact Analysis

If you use SAP MII, an attacker could steal your account information or data from other users. This may lead to identity theft, unauthorized access to systems, or further exploitation of your account. The impact is limited to confidentiality breaches.

Compliance Impact

This vulnerability could violate data protection regulations like GDPR or HIPAA by exposing sensitive user data. Organizations may face compliance penalties, legal consequences, or reputational damage due to unauthorized data access.

Mitigation Strategies

Apply the latest security patches provided by SAP for SAP Manufacturing Integration and Intelligence (MII) to address the authorization check vulnerability. Ensure proper access controls are enforced to restrict low-privileged users from accessing sensitive information.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-58244. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart