Update: CVE-2026-0503 - Missing Authorization check in in SAP ERP Central Component and SAP S/4HANA (SAP ...

Update: CVE-2026-0503 - Missing Authorization check in in SAP ERP Central Component and SAP S/4HANA (SAP ...

CVE ID : CVE-2026-0503 Published : Jan. 13, 2026, 2:15 a.m. | 36 minutes ago Description : Due to missing authorization check in the SAP ERP Central Component (SAP ECC) and SAP S/4HANA (SAP EHS Management), an attacker could extract hardcoded clear-text credentials and bypass the password authentication check by manipulating user parameters. Upon successful exploitation, the attacker can access, modify or delete certain change pointer information within EHS objects in the application which might further affect the subsequent systems. This vulnerability leads to a low impact on confidentiality and integrity of the application with no affect on the availability. Severity: 6.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
LOW
Published
Jan. 13, 2026

Source: Telegram CVE Monitor