Insufficient Authorization in SAP Incentive and Commission Management
CVE-2026-40134
4.3MEDIUM
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 12 May 2026
What is CVE-2026-40134?
The SAP Incentive and Commission Management application has a security flaw stemming from insufficient authorization checks. This issue permits authenticated users to invoke a remote-enabled function module, which can lead to unauthorized table update operations. While this vulnerability poses low risk to the integrity of data, it does not compromise the confidentiality or availability of the application. It is crucial for organizations using this software to remain vigilant and apply necessary security measures following the guidance in SAP's security notes.
Affected Version(s)
SAP Incentive and Commission Management SAP_APPL 618
SAP Incentive and Commission Management S4CORE 102
SAP Incentive and Commission Management 103