CVE-2026-23688

MEDIUM

SAP Fiori App Manage Service Entry Sheets - Privilege Escalation

Title source: llm
STIX 2.1

Description

SAP Fiori App Manage Service Entry Sheets does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This has low impact on integrity, confidentiality and availability are not impacted.

References (2)

Core 2
Core References
Permissions Required
https://me.sap.com/notes/3215823

Scores

CVSS v3 4.3
EPSS 0.0004
EPSS Percentile 12.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-862
Status published
Products (6)
sap/s4core 102
sap/s4core 103
sap/s4core 104
sap/s4core 105
sap/s4core 106
sap/s4core 107
Published Feb 10, 2026
Tracked Since Feb 18, 2026