CVE-2026-24319: SAP Business One

Medium severity, CVSS 5.8. EPSS: 0.1% chance of exploitation in the next 30 days.

In SAP Business One, sensitive information is written to the application�s memory dump files without obfuscation. Gaining access to this information could potentially lead to unauthorized operations within the B1 environment, including modification of company data. This issue results in a high impact on confidentiality and integrity, with no impact on availability.

Affected products

  • SAP Business One: version 10.0 only

Published 2026-02-10. Last modified 2026-06-17.