SAPCVE-2026-58245
SAP Advanced Planning and Optimization: hard-coded credentials
Low3.8CVE-2026-58245 · Published Aug 11, 2026 · updated Aug 26, 2026
SAP Advanced Planning and Optimization (Model Mix Planning) contains a hardcoded credential within the source code of the application to perform authorization check to access certain functionalities in the application. An attacker with high privileges could leverage this hardcoded credential to bypass authorization and delete specific planning-related restrictions in the application. Successful exploitation could result in a low impact on confidentiality and integrity, with no impact on availability of the application.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| SAP Advanced Planning and Optimization (Model Mix Planning) Product | <= SCMAPO 713 | No fix yet |
| <= 714 | No fix yet | |
| <= S4CORE 102 | No fix yet | |
| <= 103 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-798
More SAP advisories
All SAP| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 11 | SAP Commerce Cloud (Data Hub Adapter): remote code execution | Critical10.0 | No fix yet |
| Aug 11 | SAP Business AI Platform (Approuter): improper signature check | Medium5.9 | No fix yet |
| Aug 11 | SAP Business AI Platform (Approuter): path traversal | Medium5.9 | No fix yet |
| Aug 11 | SAP Approuter does not sufficiently sanitize certain request headers before... | Medium5.3 | No fix yet |
| Aug 11 | SAP NetWeaver Application Server ABAP: cross-site scripting | Medium6.3 | No fix yet |
| Aug 11 | SAP BusinessObjects Business Intelligence Platform (Central : hard-coded key | High7.9 | No fix yet |