CVE-2026-0503: Missing Authorization check in in SAP ERP Central Component and SAP S/4HANA (SAP EHS Management)
Due to missing authorization check in the SAP ERP Central Component (SAP ECC) and SAP S/4HANA (SAP EHS Management), an attacker could extract hardcoded clear-text credentials and bypass the password authentication check by manipulating user parameters. Upon successful exploitation, the attacker can access, modify or delete certain change pointer information within EHS objects in the application which might further affect the subsequent systems. This vulnerability leads to a low impact on confidentiality and integrity of the application with no affect on the availability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0503?
CVE-2026-0503 is rated as a critical vulnerability due to its potential for unauthorized access and credential extraction.
How do I fix CVE-2026-0503?
To fix CVE-2026-0503, apply the latest security patches provided by SAP for both SAP ERP Central Component and SAP S/4HANA.
Which versions of software are affected by CVE-2026-0503?
CVE-2026-0503 affects SAP ERP Central Component and SAP S/4HANA without specified version limitations.
What impact does CVE-2026-0503 have on organizations?
CVE-2026-0503 may allow attackers to bypass authentication and access sensitive information, posing significant security risks.
Is there a workaround for CVE-2026-0503?
Currently, there is no official workaround for CVE-2026-0503; patching is the recommended solution.