Skip to content
SAPCVE-2026-58245

SAP Advanced Planning and Optimization: hard-coded credentials

Low3.8CVE-2026-58245 · Published Aug 11, 2026 · updated Aug 26, 2026

SAP Advanced Planning and Optimization (Model Mix Planning) contains a hardcoded credential within the source code of the application to perform authorization check to access certain functionalities in the application. An attacker with high privileges could leverage this hardcoded credential to bypass authorization and delete specific planning-related restrictions in the application. Successful exploitation could result in a low impact on confidentiality and integrity, with no impact on availability of the application.

SAP advisory

Affected versions

PackageAffectedFixed in
SAP Advanced Planning and Optimization (Model Mix Planning)
Product
<= SCMAPO 713No fix yet
<= 714No fix yet
<= S4CORE 102No fix yet
<= 103No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-798

More SAP advisories

All SAP
Advisory
SAP Commerce Cloud (Data Hub Adapter): remote code execution
Critical10.0Aug 11
SAP Business AI Platform (Approuter): improper signature check
Medium5.9Aug 11
SAP Business AI Platform (Approuter): path traversal
Medium5.9Aug 11
SAP Approuter does not sufficiently sanitize certain request headers before...
Medium5.3Aug 11
SAP NetWeaver Application Server ABAP: cross-site scripting
Medium6.3Aug 11
SAP BusinessObjects Business Intelligence Platform (Central : hard-coded key
High7.9Aug 11

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.