VDB

CVE-2026-44771

CVE-2026-44771 PUBLISHED CVSS 4.3 MEDIUM

Reported by sap · Published July 14, 2026

SAP S/4HANA Draft operation does not perform necessary authorization checks for an authenticated user, a restricted user could access information within the entity resulting in escalation of privileges. This results in low impact on confidentiality, with no impact on integrity and availability of the application.

Risk Scores

CVSS 3.1
4.3
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Affected Products

VendorProductVersions
SAP_SESAP S/4HANA (Draft operation)S4CORE 108
SAP_SESAP S/4HANA (Draft operation)S4CORE 108

Timeline

  • Jul 14, 2026 EPSS Score
  • Jul 14, 2026 Coalition ESS Score
  • Jul 14, 2026 CVE Published
  • Jul 14, 2026 CVE Updated

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›