CVE-2026-24313 identifies an authorization bypass vulnerability within the SAP Solution Tools Plug-In (ST-PI), enabling authenticated users to disclose system information. Rated as medium severity (CVSS 5.0), this flaw requires low privileges and complexity for network exploitation, resulting in a low impact on confidentiality with no compromise to integrity or availability. Currently, there is no indication of active exploitation, public exploit code availability, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| SAP SE | SAP Solution Tools Plug-In (ST-PI) | 2008_1_710, 740, 758, ST-PI 2008_1_700CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.