AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2026-24312

MEDIUM · CVSS 5.2 EPSS 0.17%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2026-02-10 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 5.2. See the original NVD description below for full technical details.

CVE
CVE-2026-24312
Severity
MEDIUM
CVSS
5.2
EPSS
0.17%

Original NVD Description

An erroneous authorization check in SAP Business Workflow leads to privilege escalation. An authenticated administrative user can bypass role restrictions by leveraging permissions from a less sensitive function to execute unauthorized, high-privilege actions. This has a high impact on data integrity, with low impact on confidentiality and no impact on availability of the application.

Related CVEs

Other vulnerabilities affecting the same vendor(s)