Privilege Escalation Vulnerability in SAP Business Workflow
CVE-2026-24312

5.2MEDIUM

Key Information:

Vendor

SAP

Vendor
CVE Published:
10 February 2026

What is CVE-2026-24312?

A flaw in the authorization mechanism within SAP Business Workflow allows authenticated administrative users to circumvent role-based restrictions. By exploiting permissions from lower-level functions, these users can perform unauthorized actions that compromise data integrity significantly. This vulnerability calls for immediate attention, as it can lead to severe impacts on business processes and data management.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

SAP Business Workflow SAP_BASIS 752

SAP Business Workflow SAP_BASIS 753

SAP Business Workflow SAP_BASIS 754

References

CVSS V3.1

Score:
5.2
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.