Description
Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence, an unauthenticated remote attacker could access scheduling-related application functions without proper authorization validation. Successful exploitation could allow the attacker to retrieve, create, modify, or delete application-managed scheduling data, causing a low impact on confidentiality, integrity, and availability.
Published: 2026-08-11
Score: 7.3 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability stems from a missing authorization check that allows an unauthenticated remote attacker to invoke scheduling‑related functions without credentials. The attacker can read, create, modify or delete scheduling data, resulting in unauthorized data access and potential integrity loss. The overall impact on confidentiality, integrity and availability is low, but the lack of authentication permits exploitation without user interaction.

Affected Systems

SAP Manufacturing Integration and Intelligence from SAP SE is affected. Specific version information was not disclosed; therefore, all currently deployed releases that have not yet applied the vendor’s patch are potentially vulnerable.

Risk and Exploitability

The CVSS base score of 7.3 denotes high severity. EPSS is not available, so the exploitation probability is uncertain, and the vulnerability is not listed in the CISA KEV catalog. Because the flaw permits remote unauthenticated access, the attack vector is likely network‑based, and an attacker can exploit it without additional credentials. The risk is moderate to high for environments that expose the scheduling API.

Generated by OpenCVE AI on August 11, 2026 at 01:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the SAP security update referenced in SAP Note 3758657 to add the missing authorization check.
  • Restrict network access to the scheduling APIs until the patch can be applied, or disable the exposed scheduling functions if possible.
  • Review and enforce least‑privilege access controls on scheduling data to prevent unauthorized modification.

Generated by OpenCVE AI on August 11, 2026 at 01:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 11 Aug 2026 00:45:00 +0000

Type Values Removed Values Added
Description Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence, an unauthenticated remote attacker could access scheduling-related application functions without proper authorization validation. Successful exploitation could allow the attacker to retrieve, create, modify, or delete application-managed scheduling data, causing a low impact on confidentiality, integrity, and availability.
Title Missing Authorization Check in SAP Manufacturing Integration and Intelligence
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published:

Updated: 2026-08-11T00:12:05.175Z

Reserved: 2026-05-07T18:39:44.146Z

Link: CVE-2026-44765

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-11T01:30:04Z

Weaknesses