CVE-2026-58245: Hard-coded Credentials in SAP Advanced Planning and Optimization (Model Mix Planning)
SAP Advanced Planning and Optimization (Model Mix Planning) contains a hardcoded credential within the source code of the application to perform authorization check to access certain functionalities in the application. An attacker with high privileges could leverage this hardcoded credential to bypass authorization and delete specific planning-related restrictions in the application. Successful exploitation could result in a low impact on confidentiality and integrity, with no impact on availability of the application.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-58245?
The severity of CVE-2026-58245 is low, with a CVSS score of 3.8.
What types of vulnerabilities are associated with CVE-2026-58245?
CVE-2026-58245 is associated with hard-coded credentials in SAP Advanced Planning and Optimization (Model Mix Planning).
How do I fix CVE-2026-58245?
To fix CVE-2026-58245, update SAP Advanced Planning and Optimization (Model Mix Planning) to the latest version that addresses this hard-coded credential issue.
What are the potential impacts of CVE-2026-58245?
An attacker with high privileges could leverage the hard-coded credentials in CVE-2026-58245 to bypass authorization checks.
Who is affected by CVE-2026-58245?
The vulnerability in CVE-2026-58245 affects users of SAP Advanced Planning and Optimization (Model Mix Planning) software.