Design Flaw in SAP Customer Checkout Allows Unauthorized Data Modification
CVE-2026-24311

5.6MEDIUM

Key Information:

Vendor

SAP

Vendor
CVE Published:
10 March 2026

What is CVE-2026-24311?

The SAP Customer Checkout application contains a significant design flaw that allows for the local storage of operational data with reversible protection mechanisms. When users engage with the application, there is potential for unauthorized data modifications to occur without proper validation. This situation can lead to alterations in the application's behavior during startup, posing serious risks to the application's confidentiality and integrity.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

SAP Customer Checkout 2.0 SAP_CUSTOMER_CHECKOUT 2.0

References

CVSS V3.1

Score:
5.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.