Denial of Service Vulnerability in SAP Software Products
CVE-2026-23689

7.7HIGH

Key Information:

Vendor

SAP

Vendor
CVE Published:
10 February 2026

What is CVE-2026-23689?

An uncontrolled resource consumption vulnerability allows an authenticated attacker with regular user privileges to exploit SAP software products. This is achieved by invoking a remote-enabled function module with an excessively large loop-control parameter, leading to prolonged execution loops. The excessive resource consumption can result in a denial-of-service condition, making systems unavailable to legitimate users, while ensuring that confidentiality and integrity are not compromised.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

SAP Supply Chain Management SCMAPO 713

SAP Supply Chain Management 714

SAP Supply Chain Management SCM 700

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.