SAP Business Workflow Privilege Escalation Vulnerability

Vulnerability

A vulnerability in SAP Business Workflow allows for privilege escalation due to a faulty authorization check. An authenticated administrative user can exploit this flaw to bypass role restrictions, using permissions from a less sensitive function to perform unauthorized high-privilege actions. This vulnerability significantly threatens data integrity, while having a low impact on confidentiality and no effect on application availability.

Impact

Exploitation of this vulnerability could lead to unauthorized high-privilege actions being performed by an administrative user, bypassing established role restrictions and potentially compromising data integrity.

Remediation

Users are advised to consult the SAP Security Notes for guidance on addressing this vulnerability. SAP Security Notes can be accessed through the SAP for Me platform, specifically on SAP Security Patch Day, which occurs on the second Tuesday of each month.

Added: Feb 10, 2026, 6:35 AM
Updated: Feb 10, 2026, 6:35 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
4.8
remediation
0.0
relevance
3.0
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.