CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 4.3. It may be remotely exploitable.
CVE
CVE-2026-24326
Severity
MEDIUM
CVSS
4.3
EPSS
0.20%
Original NVD Description
Due to a missing authorization check in the Disconnected Operations of the SAP S/4HANA Defense & Security, an attacker with user privileges could call remote-enabled function modules to do direct update on standard SAP database table . This results in low impact on integrity, with no impact on confidentiality or availability of the application.
Related CVEs
Other vulnerabilities affecting the same vendor(s)