SAPCVE-2026-44771
SAP S/4HANA (Draft operation): privilege escalation
Medium4.3CVE-2026-44771 · Published Jul 14, 2026
SAP S/4HANA Draft operation does not perform necessary authorization checks for an authenticated user, a restricted user could access information within the entity resulting in escalation of privileges. This results in low impact on confidentiality, with no impact on integrity and availability of the application.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| SAP S/4HANA (Draft operation) Product | <= S4CORE 108 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-862
More SAP advisories
All SAP| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 14 | SAP Commerce Cloud could retain a sample OAuth2 client with publicly documented... | Critical9.1 | No fix yet |
| Jul 14 | SAP @ui5/webcomponents-base: clickjacking | Medium6.1 | No fix yet |
| Jul 14 | SAP CRM (WebClient UI): attacker could inject | Medium4.1 | No fix yet |
| Jul 14 | SAP S/4HANA Project Management (PPM-PRO): SQL injection | Medium5.5 | No fix yet |
| Jul 14 | SAP S/4 HANA (Create Single Payment): missing authorization | Medium4.3 | No fix yet |
| Jul 14 | SAP Change and Transport System Attach Tool (ctsattach): unsafe deserialization | High7.6 | No fix yet |