Access Vulnerability in SAP Product Designer by SAP
CVE-2026-0497
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 13 January 2026
What is CVE-2026-0497?
The SAP Product Designer Web UI vulnerability allows authenticated non-administrative users to access certain non-sensitive information due to improper access control in Business Server Pages. This exposure compromises confidentiality, potentially leading to unauthorized data visibility but does not affect the integrity or availability of the application.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Business Server Pages Application (Product Designer Web UI) SAP_APPL 618
Business Server Pages Application (Product Designer Web UI) S4CORE 102
Business Server Pages Application (Product Designer Web UI) 103
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved