SAP Fiori App Manage Service Entry Sheets does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This has low impact on integrity, confidentiality and availability are not impacted.
References
| Link | Resource |
|---|---|
| https://me.sap.com/notes/3215823 | Permissions Required |
| https://url.sap/sapsecuritypatchday | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
17 Feb 2026, 15:58
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://me.sap.com/notes/3215823 - Permissions Required | |
| References | () https://url.sap/sapsecuritypatchday - Vendor Advisory | |
| CPE | cpe:2.3:a:sap:s4core:106:*:*:*:*:*:*:* cpe:2.3:a:sap:s4core:102:*:*:*:*:*:*:* cpe:2.3:a:sap:s4core:104:*:*:*:*:*:*:* cpe:2.3:a:sap:s4core:105:*:*:*:*:*:*:* cpe:2.3:a:sap:s4core:107:*:*:*:*:*:*:* cpe:2.3:a:sap:s4core:103:*:*:*:*:*:*:* |
|
| First Time |
Sap s4core
Sap |
|
| Summary |
|
10 Feb 2026, 04:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-10 04:16
Updated : 2026-02-17 15:58
NVD link : CVE-2026-23688
Mitre link : CVE-2026-23688
CVE.ORG link : CVE-2026-23688
JSON object : View
Products Affected
sap
- s4core
CWE
CWE-862
Missing Authorization
