CVE-2026-0511 Details
Description
SAP Fiori App Intercompany Balance Reconciliation does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This has high impact on confidentiality and integrity of the application ,availability is not impacted.
A vulnerability in the SAP Fiori App Intercompany Balance Reconciliation has been identified, where the application fails to implement necessary authorization checks for authenticated users. This oversight allows for unauthorized privilege escalation, which could be exploited to gain elevated rights within the application. The vulnerability significantly impacts the application's confidentiality and integrity, although its availability remains unaffected.
Users are advised to consult the SAP Security Notes for guidance on addressing this vulnerability. SAP Security Notes can be accessed through the SAP for Me platform, where users can find the complete list of all security notes and prioritize their implementation. For SAP NetWeaver based products, security fixes are delivered with the support packages.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jan 13, 2026CISA-ADP
Assessed Jan 14, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://me.sap.com/notes/3565506 | [email protected] | Permission RequiredVendor |
| https://url.sap/sapsecuritypatchday | [email protected] | AdvisoryVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-862 | Missing Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| SAP Fiori App Intercompany Balance Reconciliation | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 13, 2026 | New CVE Received | [email protected] |
Volerion