cbcvebase.
CVE-2026-23681
published 2026-02-10

CVE-2026-23681: Due to missing authorization check in a function module in SAP Support Tools Plug-In, an authenticated attacker could invoke specific function modules to…

PriorityP423medium4.3CVSS 3.1
AVNACLPRLUINSUCLINAN
EPSS
0.17%
6.4th percentile
Due to missing authorization check in a function module in SAP Support Tools Plug-In, an authenticated attacker could invoke specific function modules to retrieve information about the system and its configuration. This disclosure of the system information could assist the attacker to plan subsequent attacks. This vulnerability has a low impact on the confidentiality of the application, with no effect on its integrity or availability.

Affected

8 ranges
VendorProductVersion rangeFixed in
sapsolution_tools_plug-in
sapsolution_tools_plug-in
sapsolution_tools_plug-in
sapsolution_tools_plug-in
sap_sesap_support_tools_plug-in
sap_sesap_support_tools_plug-in
sap_sesap_support_tools_plug-in
sap_sesap_support_tools_plug-in
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.