VDB
CVE-2026-40133
CVE-2026-40133
PUBLISHED
CVSS 6.300000190734863 MEDIUM
Due to missing authorization check in SAP S/4HANA Condition Maintenance, an authenticated attacker could gain unauthorized access to view and modify condition table records, resulting in low impact on the confidentiality and integrity of the data. Additionally, this vulnerability may prevent the legitimate user from accessing the records, causing low impact on application availability.
EPSS 0.02% · 3.2th percentile
Risk Scores
CVSS 3.1
6.300000190734863
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
EPSS Score
0.02%
3.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| SAP_SE | SAP S/4HANA Condition Maintenance | S4CORE 102, 103, 104 |
Timeline
- May 12, 2026 CVE Published
- May 12, 2026 PoC Published
- May 12, 2026 Security Advisory
- May 12, 2026 CVE Updated
- May 18, 2026 EPSS Score
- May 19, 2026 EPSS Score
- May 20, 2026 EPSS Score
- May 21, 2026 EPSS Score
- May 22, 2026 EPSS Score
- May 23, 2026 EPSS Score
- May 24, 2026 EPSS Score
- May 25, 2026 EPSS Score