Junglewise Threat Intelligence

CVE-2026-40132: SAP Strategic Enterprise Management missing authorization check in Scorecard Wizard

CVE-2026-40132 · Severity: medium · CVSS 5.4 · Published 2026-05-12

Vendors: SAP.

Executive brief

SAP Strategic Enterprise Management, a tool used by organizations for performance monitoring and risk evaluation, contains a security flaw in its Scorecard Wizard. An authenticated user can bypass security checks to view sensitive information they are not authorized to see. Furthermore, an attacker can manipulate default settings and data fields, potentially leading to inaccurate risk assessments and misleading business reports.

Technical details

A missing authorization check (CWE-862) exists within the Scorecard Wizard of the Business Server Pages (BSP) component of SAP Strategic Enterprise Management. An authenticated attacker with low privileges can exploit this vulnerability over the network to access unauthorized information or modify value fields and default settings. Such modifications can result in the falsification of risk evaluations by lowering assessed risk levels. The vulnerability impacts data confidentiality and integrity but does not affect system availability. SAP has released security note 3721959 to address this issue.

Affected products

  • SAP Strategic Enterprise Management Scorecard Wizard in Business Server Pages

Timeline

  • 2026-05-12: advisory: Initial publication of CVE-2026-40132 by SAP and NVD.

References