Authorization Flaw in SAP Manufacturing Integration and Intelligence
CVE-2026-58244

4.3MEDIUM

Key Information:

Vendor

SAP

Vendor
CVE Published:
11 August 2026

What is CVE-2026-58244?

SAP Manufacturing Integration and Intelligence (MII) lacks adequate authorization checks for specific application functions, enabling low-privileged authenticated attackers to gain access to confidential user information that is typically reserved for privileged accounts. Exploitation of this vulnerability may lead to unauthorized access to user account information, potentially facilitating further attacks. While the impact on data confidentiality is low, it poses risks that should not be underestimated. Organizations utilizing SAP MII should remain vigilant and apply security patches promptly to mitigate this risk.

Affected Version(s)

SAP Manufacturing Integration and Intelligence XMII 15.4

SAP Manufacturing Integration and Intelligence 15.5

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.