SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2026-24312

An erroneous authorization check in SAP Business Workflow leads to privilege escalation.

MEDIUM 5.2EPSS 0.18%

Does this matter?

Lower severity and a low EPSS score (0.18%). Track it; it rarely justifies an emergency change on its own.

Description

An erroneous authorization check in SAP Business Workflow leads to privilege escalation. An authenticated administrative user can bypass role restrictions by leveraging permissions from a less sensitive function to execute unauthorized, high-privilege actions. This has a high impact on data integrity, with low impact on confidentiality and no impact on availability of the application.

CVSS 3.1
5.2 MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:H/A:N
EPSS
0.18% probability · 7th percentile
CISA KEV
Not listed
Weakness
CWE-862
Affected
sap/sap basis
Source
cna@sap.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.