CVE-2026-24326

Due to a missing authorization check in the Disconnected Operations of the SAP S/4HANA Defense & Security, an attacker with user privileges could call remote-enabled function modules to do direct update on standard SAP database table . This results in low impact on integrity, with no impact on confidentiality or availability of the application.
References
Link Resource
https://me.sap.com/notes/3678009 Permissions Required
https://url.sap/sapsecuritypatchday Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sap:s\/4hana_defense_\&_security:600:*:*:*:*:*:*:*
cpe:2.3:a:sap:s\/4hana_defense_\&_security:603:*:*:*:*:*:*:*
cpe:2.3:a:sap:s\/4hana_defense_\&_security:604:*:*:*:*:*:*:*
cpe:2.3:a:sap:s\/4hana_defense_\&_security:605:*:*:*:*:*:*:*
cpe:2.3:a:sap:s\/4hana_defense_\&_security:606:*:*:*:*:*:*:*
cpe:2.3:a:sap:s\/4hana_defense_\&_security:616:*:*:*:*:*:*:*
cpe:2.3:a:sap:s\/4hana_defense_\&_security:617:*:*:*:*:*:*:*
cpe:2.3:a:sap:s\/4hana_defense_\&_security:618:*:*:*:*:*:*:*
cpe:2.3:a:sap:s\/4hana_defense_\&_security:619:*:*:*:*:*:*:*
cpe:2.3:a:sap:s\/4hana_defense_\&_security:800:*:*:*:*:*:*:*
cpe:2.3:a:sap:s\/4hana_defense_\&_security:801:*:*:*:*:*:*:*
cpe:2.3:a:sap:s\/4hana_defense_\&_security:802:*:*:*:*:*:*:*
cpe:2.3:a:sap:s\/4hana_defense_\&_security:803:*:*:*:*:*:*:*
cpe:2.3:a:sap:s\/4hana_defense_\&_security:804:*:*:*:*:*:*:*
cpe:2.3:a:sap:s\/4hana_defense_\&_security:805:*:*:*:*:*:*:*
cpe:2.3:a:sap:s\/4hana_defense_\&_security:806:*:*:*:*:*:*:*
cpe:2.3:a:sap:s\/4hana_defense_\&_security:807:*:*:*:*:*:*:*
cpe:2.3:a:sap:s\/4hana_defense_\&_security:808:*:*:*:*:*:*:*
cpe:2.3:a:sap:s\/4hana_defense_\&_security:809:*:*:*:*:*:*:*

History

17 Feb 2026, 15:13

Type Values Removed Values Added
CPE cpe:2.3:a:sap:s\/4hana_defense_\&_security:803:*:*:*:*:*:*:*
cpe:2.3:a:sap:s\/4hana_defense_\&_security:600:*:*:*:*:*:*:*
cpe:2.3:a:sap:s\/4hana_defense_\&_security:618:*:*:*:*:*:*:*
cpe:2.3:a:sap:s\/4hana_defense_\&_security:619:*:*:*:*:*:*:*
cpe:2.3:a:sap:s\/4hana_defense_\&_security:801:*:*:*:*:*:*:*
cpe:2.3:a:sap:s\/4hana_defense_\&_security:805:*:*:*:*:*:*:*
cpe:2.3:a:sap:s\/4hana_defense_\&_security:603:*:*:*:*:*:*:*
cpe:2.3:a:sap:s\/4hana_defense_\&_security:802:*:*:*:*:*:*:*
cpe:2.3:a:sap:s\/4hana_defense_\&_security:800:*:*:*:*:*:*:*
cpe:2.3:a:sap:s\/4hana_defense_\&_security:604:*:*:*:*:*:*:*
cpe:2.3:a:sap:s\/4hana_defense_\&_security:804:*:*:*:*:*:*:*
cpe:2.3:a:sap:s\/4hana_defense_\&_security:606:*:*:*:*:*:*:*
cpe:2.3:a:sap:s\/4hana_defense_\&_security:807:*:*:*:*:*:*:*
cpe:2.3:a:sap:s\/4hana_defense_\&_security:808:*:*:*:*:*:*:*
cpe:2.3:a:sap:s\/4hana_defense_\&_security:616:*:*:*:*:*:*:*
cpe:2.3:a:sap:s\/4hana_defense_\&_security:605:*:*:*:*:*:*:*
cpe:2.3:a:sap:s\/4hana_defense_\&_security:806:*:*:*:*:*:*:*
cpe:2.3:a:sap:s\/4hana_defense_\&_security:809:*:*:*:*:*:*:*
cpe:2.3:a:sap:s\/4hana_defense_\&_security:617:*:*:*:*:*:*:*
References () https://me.sap.com/notes/3678009 - () https://me.sap.com/notes/3678009 - Permissions Required
References () https://url.sap/sapsecuritypatchday - () https://url.sap/sapsecuritypatchday - Vendor Advisory
First Time Sap
Sap s\/4hana Defense \& Security
Summary
  • (es) Debido a una verificación de autorización faltante en las Operaciones Desconectadas de SAP S/4HANA Defense & Security, un atacante con privilegios de usuario podría llamar módulos de función habilitados remotamente para realizar una actualización directa en una tabla de base de datos SAP estándar. Esto resulta en un impacto bajo en la integridad, sin impacto en la confidencialidad o disponibilidad de la aplicación.

10 Feb 2026, 04:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-10 04:16

Updated : 2026-02-17 15:13


NVD link : CVE-2026-24326

Mitre link : CVE-2026-24326

CVE.ORG link : CVE-2026-24326


JSON object : View

Products Affected

sap

  • s\/4hana_defense_\&_security
CWE
CWE-862

Missing Authorization