Missing Authorization Check in SAP Incentive and Commission Management
CVE-2026-40134
4.3MEDIUM
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 12 May 2026
What is CVE-2026-40134?
Due to insufficient authorization checks in the SAP Incentive and Commission Management application, authenticated users could invoke a remote-enabled function module to perform table update operations. This vulnerability has a low impact on integrity with no impact on confidentiality and availability of the application.
Affected Version(s)
SAP Incentive and Commission Management SAP_APPL 618
SAP Incentive and Commission Management S4CORE 102
SAP Incentive and Commission Management 103