CVE-2026-58245
Received Received - Intake

Hardcoded Credentials in SAP APO Model Mix Planning

Vulnerability report for CVE-2026-58245, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-11

Last updated on: 2026-08-11

Assigner: SAP SE

Description

SAP Advanced Planning and Optimization (Model Mix Planning) contains a hardcoded credential within the source code of the application to perform authorization check to access certain functionalities in the application. An attacker with high privileges could leverage this hardcoded credential to bypass authorization and delete specific planning-related restrictions in the application. Successful exploitation could result in a low impact on confidentiality and integrity, with no impact on availability of the application.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-11
Last Modified
2026-08-11
Generated
2026-08-11
AI Q&A
2026-08-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
sap advanced_planning_and_optimization *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-798 The product contains hard-coded credentials, such as a password or cryptographic key.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

SAP Advanced Planning and Optimization (Model Mix Planning) has a hardcoded credential in its source code. This credential is used for authorization checks to access certain application functionalities. An attacker with high privileges could exploit this to bypass authorization and remove planning-related restrictions.

Detection Guidance

Detection of this vulnerability requires reviewing the source code of SAP Advanced Planning and Optimization (Model Mix Planning) for hardcoded credentials. No specific commands are provided in the context. Manual code inspection or using static analysis tools to search for hardcoded credentials in the application is recommended.

Impact Analysis

An attacker could delete specific planning restrictions, potentially altering business operations. The impact is low on confidentiality and integrity, with no effect on availability. Only users with high privileges could exploit this.

Compliance Impact

This vulnerability involves hardcoded credentials that could allow unauthorized access to sensitive planning-related data. Such access could potentially lead to violations of confidentiality and integrity requirements under GDPR and HIPAA, depending on the data processed by the application. However, the specific impact on compliance depends on the data involved and organizational context.

Mitigation Strategies

Immediate mitigation steps include updating SAP Advanced Planning and Optimization to the latest version where the hardcoded credential has been removed. Additionally, restrict high-privilege access to the application and monitor for unauthorized changes to planning-related restrictions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-58245. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart