Denial of Service Vulnerability in SAP Software Products
CVE-2026-23689
7.7HIGH
What is CVE-2026-23689?
An uncontrolled resource consumption vulnerability allows an authenticated attacker with regular user privileges to exploit SAP software products. This is achieved by invoking a remote-enabled function module with an excessively large loop-control parameter, leading to prolonged execution loops. The excessive resource consumption can result in a denial-of-service condition, making systems unavailable to legitimate users, while ensuring that confidentiality and integrity are not compromised.
Affected Version(s)
SAP Supply Chain Management SCMAPO 713
SAP Supply Chain Management 714
SAP Supply Chain Management SCM 700