CVE-2026-24312 is a privilege escalation vulnerability in SAP Business Workflow (SAP_BASIS) where an authenticated administrative user can bypass role restrictions. By exploiting an erroneous authorization check, an attacker can leverage lower-privilege functions to execute unauthorized, high-privilege actions, primarily impacting data integrity. Rated Medium severity (CVSS 5.2), this vulnerability requires high privileges and user interaction, but has a low attack complexity. Currently, there is no known public exploit code, active exploitation, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
752CPE matchmatch criteria | cpe:2.3:a:sap:sap_basis:752:*:*:*:*:*:*:* | ||
753CPE matchmatch criteria | cpe:2.3:a:sap:sap_basis:753:*:*:*:*:*:*:* | ||
754CPE matchmatch criteria | cpe:2.3:a:sap:sap_basis:754:*:*:*:*:*:*:* | ||
755CPE matchmatch criteria | cpe:2.3:a:sap:sap_basis:755:*:*:*:*:*:*:* | ||
756CPE matchmatch criteria | cpe:2.3:a:sap:sap_basis:756:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:H/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.