CVE-2026-58245: SAP SE SAP Advanced Planning And Optimization Model Mix Planning
Low severity, CVSS 3.8. EPSS: 0.3% chance of exploitation in the next 30 days.
SAP Advanced Planning and Optimization (Model Mix Planning) contains a hardcoded credential within the source code of the application to perform authorization check to access certain functionalities in the application. An attacker with high privileges could leverage this hardcoded credential to bypass authorization and delete specific planning-related restrictions in the application. Successful exploitation could result in a low impact on confidentiality and integrity, with no impact on availability of the application.
Affected products
- SAP SE SAP Advanced Planning And Optimization Model Mix Planning: version 714 only; version S4CORE 102 only; version 103 only; version 104 only; version S4COREOP 104 only; version 105 only; …
Published 2026-08-11. Last modified 2026-08-26.