CVE-2026-58245 PUBLISHED

Hard-coded Credentials in SAP Advanced Planning and Optimization (Model Mix Planning)

Assigner: sap
Reserved: 29.06.2026 Published: 11.08.2026 Updated: 11.08.2026

SAP Advanced Planning and Optimization (Model Mix Planning) contains a hardcoded credential within the source code of the application to perform authorization check to access certain functionalities in the application. An attacker with high privileges could leverage this hardcoded credential to bypass authorization and delete specific planning-related restrictions in the application. Successful exploitation could result in a low impact on confidentiality and integrity, with no impact on availability of the application.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N
CVSS Score: 3.8

Product Status

Vendor SAP_SE
Product SAP Advanced Planning and Optimization (Model Mix Planning)
Versions Default: unaffected
  • Version SCMAPO 713 is affected
  • Version 714 is affected
  • Version S4CORE 102 is affected
  • Version 103 is affected
  • Version 104 is affected
  • Version S4COREOP 104 is affected
  • Version 105 is affected
  • Version 106 is affected
  • Version 107 is affected
  • Version 108 is affected
  • Version 109 is affected
  • Version SCM 700 is affected
  • Version 701 is affected
  • Version 702 is affected
  • Version 712 is affected

References

Problem Types