CVE-2026-24313: SAP SE SAP Solution Tools Plug-In St-Pi

Medium severity, CVSS 5.0. EPSS: 0.2% chance of exploitation in the next 30 days.

SAP Solution Tools Plug-In (ST-PI) contains a function module that does not perform the necessary authorization checks for authenticated users, allowing system information to be disclosed. This vulnerability has a low impact on confidentiality and does not affect integrity or availability.

Affected products

  • SAP SE SAP Solution Tools Plug-In St-Pi: version 2008_1_710 only; version 740 only; version 758 only

Published 2026-03-10. Last modified 2026-06-17.