Junglewise Threat Intelligence

CVE-2026-40133: SAP S/4HANA missing authorization check in Condition Maintenance

CVE-2026-40133 · Severity: medium · CVSS 6.3 · Published 2026-05-12

Vendors: SAP.

Executive brief

A security vulnerability exists in SAP S/4HANA's condition maintenance component, which is used to manage pricing and business rules. An authorized user could bypass security checks to view or change sensitive records they should not have access to. This could lead to unauthorized data modifications or prevent legitimate users from accessing necessary business information.

Technical details

A missing authorization check (CWE-862) in SAP S/4HANA Condition Maintenance allows an authenticated attacker with low privileges to bypass access controls. By exploiting this flaw over the network, an attacker can view or modify records within condition tables. This unauthorized access can compromise data integrity and confidentiality, and in some cases, lead to a denial of service for legitimate users attempting to access the same records. SAP has released security note 3718083 to address this issue.

Affected products

  • SAP S/4HANA Condition Maintenance

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory

References