Description
SAP Manufacturing Integration and Intelligence (MII) does not perform necessary authorization check on certain application function, allowing a low-privileged authenticated attacker to access information that should be restricted to privileged users. Successful exploitation could allow the attacker to access the users account information in the application, which could be leveraged to facilitate further attacks against the identified user accounts. This vulnerability results in low impact on confidentiality of the data, with no impact on the integrity and availability
Published: 2026-08-11
Score: 4.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

SAP Manufacturing Integration and Intelligence (MII) lacks an authorization check on specific application functions, enabling a low‑privileged authenticated attacker to read user account information that should be restricted. The information exposed has a small impact on confidentiality, with no effect on integrity or availability, but could be used to facilitate further attacks against the exposed user accounts.

Affected Systems

The vulnerability affects SAP Manufacturing Integration and Intelligence (SAP MII). Version details are not provided in the advisory; all installations of SAP MII should be considered potentially vulnerable until a patch is applied.

Risk and Exploitability

The CVSS score of 4.3 places this issue in the Medium range, and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog. Because the flaw requires an authenticated attacker with low privileges, the attack vector is likely an internal or remote authenticated session where the attacker can invoke the unprotected function.

Generated by OpenCVE AI on August 11, 2026 at 01:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the security patch identified in SAP Note 3781137 to restore proper authorization controls.
  • If a patch is not yet available, disable or restrict low‑privileged user access to the affected application functions until the patch can be applied.
  • Enable logging and monitoring for anomalous access to user account information within SAP MII.

Generated by OpenCVE AI on August 11, 2026 at 01:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 11 Aug 2026 00:45:00 +0000

Type Values Removed Values Added
Description SAP Manufacturing Integration and Intelligence (MII) does not perform necessary authorization check on certain application function, allowing a low-privileged authenticated attacker to access information that should be restricted to privileged users. Successful exploitation could allow the attacker to access the users account information in the application, which could be leveraged to facilitate further attacks against the identified user accounts. This vulnerability results in low impact on confidentiality of the data, with no impact on the integrity and availability
Title Missing Authorization Check in SAP Manufacturing Integration and Intelligence (MII)
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published:

Updated: 2026-08-11T00:16:44.790Z

Reserved: 2026-06-29T19:35:04.185Z

Link: CVE-2026-58244

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-11T01:30:04Z

Weaknesses