CVE-2025-26655: SAP SE SAP Just In Time
Low severity, CVSS 3.1. EPSS: 0.2% chance of exploitation in the next 30 days.
SAP Just In Time(JIT) does not perform necessary authorization checks for an authenticated user, allowing attacker to escalate privileges that would otherwise be restricted, potentially causing a low impact on the integrity of the application.Confidentiality and Availability are not impacted.
Affected products
- SAP SE SAP Just In Time: version S4CORE 102 only; version 103 only; version 104 only; version 105 only; version 106 only; version 107 only
Published 2025-03-11. Last modified 2026-06-17.