Executive brief
SAP Master Data Governance (MDG) is a platform used by organizations to manage and consolidate their business data. A security flaw in the Review Match Groups application allows low-privileged users to perform unauthorized actions that should be restricted to administrators. While this does not expose sensitive data or cause system outages, it allows unauthorized users to modify certain data settings, potentially compromising the accuracy of business records.
Technical details
A missing authorization check (CWE-862) exists within the Review Match Groups application of SAP Master Data Governance (MDG). An authenticated attacker with low-level privileges can exploit this vulnerability over the network to perform restricted actions, resulting in an escalation of privilege. The impact is limited to a low loss of integrity, as the flaw allows unauthorized modifications but does not permit data exfiltration (confidentiality) or service disruption (availability). SAP has addressed this issue in security note 3673181 as part of the June 2026 Patch Day.
Affected products
- SAP Master Data Governance (MDG)
Timeline
- 2026-06-09: advisory: SAP published security note 3673181 during the June Patch Day.
- 2026-06-09: disclosed: CVE-2026-44750 was published to the NVD.