Description
SAP Advanced Planning and Optimization (Model Mix Planning) contains a hardcoded credential within the source code of the application to perform authorization check to access certain functionalities in the application. An attacker with high privileges could leverage this hardcoded credential to bypass authorization and delete specific planning-related restrictions in the application. Successful exploitation could result in a low impact on confidentiality and integrity, with no impact on availability of the application.
Published: 2026-08-11
Score: 3.8 Low
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

SAP Advanced Planning and Optimization (Model Mix Planning) contains a hard‑coded credential in its source code that is used for authorizing certain functions. The credential can be used by anyone with privileged access to the code to bypass the application’s authorization checks and remove planning restrictions. Because the vulnerability involves only a small hard‑coded token, the potential damage is limited to confidentiality and integrity of planning data; availability remains unaffected. This weakness corresponds to CWE‑798, hard‑coded authentication non‑standard.

Affected Systems

The affected product is SAP Advanced Planning and Optimization (Model Mix Planning). No specific version ranges are listed in the advisory, so any deployment of this SAP module that has not been updated to remove the hard‑coded credential is potentially vulnerable.

Risk and Exploitability

The calculated CVSS score of 3.8 indicates low overall severity. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. The vulnerability can be exploited only by an attacker who has the ability to read the source code or diagnose the application; it does not provide network‑based remote execution. It is therefore likely limited to internal threat actors with elevated privileges.

Generated by OpenCVE AI on August 11, 2026 at 01:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the patch provided in SAP Note 3763028 to remove or protect the hard‑coded credential.
  • Upgrade to the latest SAP Advanced Planning and Optimization (Model Mix Planning) release that eliminates the hard‑coded credential.
  • Restrict file‑system permissions to the application’s source code and configuration directories so that only authorized developers and administrators can read them.

Generated by OpenCVE AI on August 11, 2026 at 01:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 11 Aug 2026 00:45:00 +0000

Type Values Removed Values Added
Description SAP Advanced Planning and Optimization (Model Mix Planning) contains a hardcoded credential within the source code of the application to perform authorization check to access certain functionalities in the application. An attacker with high privileges could leverage this hardcoded credential to bypass authorization and delete specific planning-related restrictions in the application. Successful exploitation could result in a low impact on confidentiality and integrity, with no impact on availability of the application.
Title Hard-coded Credentials in SAP Advanced Planning and Optimization (Model Mix Planning)
Weaknesses CWE-798
References
Metrics cvssV3_1

{'score': 3.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published:

Updated: 2026-08-11T00:16:55.122Z

Reserved: 2026-06-29T19:35:04.185Z

Link: CVE-2026-58245

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-11T01:30:04Z

Weaknesses
  • CWE-798

    Use of Hard-coded Credentials