CVE-2026-0503: Missing Authorization check in in SAP ERP Central Component and SAP S/4HANA (SAP EHS Management)

Published Jan 13, 2026
·
Updated

Due to missing authorization check in the SAP ERP Central Component (SAP ECC) and SAP S/4HANA (SAP EHS Management), an attacker could extract hardcoded clear-text credentials and bypass the password authentication check by manipulating user parameters. Upon successful exploitation, the attacker can access, modify or delete certain change pointer information within EHS objects in the application which might further affect the subsequent systems. This vulnerability leads to a low impact on confidentiality and integrity of the application with no affect on the availability.

Affected Software

2 affected components
SAP ERP Central Component
SAP S/4HANA

Event History

Jan 13, 2026
CVE Published
via MITRE·01:14 AM
Data Sourced
via MITRE·01:14 AM
DescriptionSeverity
Data Sourced
via NVD·02:15 AM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-0503?

CVE-2026-0503 is rated as a critical vulnerability due to its potential for unauthorized access and credential extraction.

2

How do I fix CVE-2026-0503?

To fix CVE-2026-0503, apply the latest security patches provided by SAP for both SAP ERP Central Component and SAP S/4HANA.

3

Which versions of software are affected by CVE-2026-0503?

CVE-2026-0503 affects SAP ERP Central Component and SAP S/4HANA without specified version limitations.

4

What impact does CVE-2026-0503 have on organizations?

CVE-2026-0503 may allow attackers to bypass authentication and access sensitive information, posing significant security risks.

5

Is there a workaround for CVE-2026-0503?

Currently, there is no official workaround for CVE-2026-0503; patching is the recommended solution.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203