Home

Description

Due to missing authorization check in SAP S/4HANA Condition Maintenance, an authenticated attacker could gain unauthorized access to view and modify condition table records, resulting in low impact on the confidentiality and integrity of the data. Additionally, this vulnerability may prevent the legitimate user from accessing the records, causing low impact on application availability.

PUBLISHED Reserved 2026-04-09 | Published 2026-05-12 | Updated 2026-05-12 | Assigner sap




MEDIUM: 6.3CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Problem types

CWE-862: Missing Authorization

Product status

Default status
unaffected

S4CORE 102
affected

103
affected

104
affected

105
affected

106
affected

107
affected

108
affected

109
affected

References

me.sap.com/notes/3718083

url.sap/sapsecuritypatchday

cve.org (CVE-2026-40133)

nvd.nist.gov (CVE-2026-40133)

Download JSON