Denial of Service Vulnerability in SAP Software Products
CVE-2026-23689
What is CVE-2026-23689?
An uncontrolled resource consumption vulnerability allows an authenticated attacker with regular user privileges to exploit SAP software products. This is achieved by invoking a remote-enabled function module with an excessively large loop-control parameter, leading to prolonged execution loops. The excessive resource consumption can result in a denial-of-service condition, making systems unavailable to legitimate users, while ensuring that confidentiality and integrity are not compromised.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
SAP Supply Chain Management SCMAPO 713
SAP Supply Chain Management 714
SAP Supply Chain Management SCM 700
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved