CVE-2026-40134: SAP SE SAP Incentive And Commission Management
Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.
Due to insufficient authorization checks in the SAP Incentive and Commission Management application, authenticated users could invoke a remote-enabled function module to perform table update operations. This vulnerability has a low impact on integrity with no impact on confidentiality and availability of the application.
Affected products
- SAP SE SAP Incentive And Commission Management: version S4CORE 102 only; version 103 only; version 104 only; version 105 only; version 106 only; version 107 only; …
Published 2026-05-12. Last modified 2026-06-17.