CVE-2026-24312: Missing authorization check in SAP Business Workflow
An erroneous authorization check in SAP Business Workflow leads to privilege escalation. An authenticated administrative user can bypass role restrictions by leveraging permissions from a less sensitive function to execute unauthorized, high-privilege actions. This has a high impact on data integrity, with low impact on confidentiality and no impact on availability of the application.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-24312?
CVE-2026-24312 is considered a high severity vulnerability due to the potential for privilege escalation.
How do I fix CVE-2026-24312?
To fix CVE-2026-24312, apply the latest security patches provided by SAP for the Business Workflow software.
Who is affected by CVE-2026-24312?
CVE-2026-24312 affects authenticated administrative users of SAP Business Workflow systems.
What kind of attack does CVE-2026-24312 enable?
CVE-2026-24312 enables attackers to perform unauthorized actions with elevated privileges due to missing authorization checks.
Is there a workaround for CVE-2026-24312?
Currently, there are no known workarounds for CVE-2026-24312; applying the security patches is the recommended course of action.