CVE-2026-24312 - Missing authorization check in SAP Business Workflow

CVE-2026-24312 - Missing authorization check in SAP Business Workflow

CVE ID : CVE-2026-24312 Published : Feb. 10, 2026, 4:16 a.m. | 14 minutes ago Description : An erroneous authorization check in SAP Business Workflow leads to privilege escalation. An authenticated administrative user can bypass role restrictions by leveraging permissions from a less sensitive function to execute unauthorized, high-privilege actions. This has a high impact on data integrity, with low impact on confidentiality and no impact on availability of the application. Severity: 5.2 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
HIGH
Published
Feb. 10, 2026
Impact: privilege escalation