CVE-2026-23681

Severity
4.3MEDIUM
EPSS
0.0%
top 90.05%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 10

Description

Due to missing authorization check in a function module in SAP Support Tools Plug-In, an authenticated attacker could invoke specific function modules to retrieve information about the system and its configuration. This disclosure of the system information could assist the attacker to plan subsequent attacks. This vulnerability has a low impact on the confidentiality of the application, with no effect on its integrity or availability.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages2 packages

CVEListV5sap_se/sap_support_tools_plug-in4 versions+3
NVDsap/solution_tools_plug-in4 versions+3

🔴Vulnerability Details

2
GHSA
GHSA-rfxm-73cg-f6jv: Due to missing authorization check in a function module in SAP Support Tools Plug-In, an authenticated attacker could invoke specific function modules2026-02-10
CVEList
Missing Authorization check in a function module in SAP Support Tools Plug-In2026-02-10
CVE-2026-23681 (MEDIUM CVSS 4.3) | Due to missing authorization check | cvebase.io