CVE-2025-26656: SAP SE s/4hana Manage Purchasing Info Records
Medium severity, CVSS 4.3. EPSS: 0.2% chance of exploitation in the next 30 days.
OData Service in Manage Purchasing Info Records does not perform necessary authorization checks for an authenticated user, allowing an attacker to escalate privileges. This has low impact on integrity of the application.
Affected products
- SAP SE s/4hana Manage Purchasing Info Records: version S4CORE 105 only; version 106 only; version 107 only; version 108 only
Published 2025-03-11. Last modified 2026-06-17.