Junglewise Threat Intelligence

CVE-2026-40134: SAP Incentive and Commission Management missing authorization check

CVE-2026-40134 · Severity: medium · CVSS 4.3 · Published 2026-05-12

Vendors: SAP.

Executive brief

SAP Incentive and Commission Management is a tool used by businesses to manage sales commissions and incentive programs. A security flaw in this application allows logged-in users to perform unauthorized updates to internal database tables. While this does not allow users to steal data or crash the system, it could lead to minor unauthorized changes in business records.

Technical details

A missing authorization check (CWE-862) exists in the SAP Incentive and Commission Management application. An authenticated attacker with low privileges can exploit this by invoking a specific remote-enabled function module (RFM) to perform unauthorized table update operations. The attack is reachable over the network and requires no user interaction. The impact is limited to a low loss of integrity, as the vulnerability does not facilitate data exfiltration (confidentiality) or service disruption (availability). SAP has addressed this in SAP Security Note 3718508.

Affected products

  • SAP Incentive and Commission Management

Timeline

  • 2026-05-12: advisory: SAP published security note 3718508 during the May 2026 Patch Day.
  • 2026-05-12: disclosed: CVE-2026-40134 was published to the NVD.

References