Junglewise Threat Intelligence

CVE-2026-44771: SAP S/4HANA missing authorization check in Draft operation

CVE-2026-44771 · Severity: medium · CVSS 4.3 · Published 2026-07-14

Vendors: SAP SE.

Executive brief

SAP S/4HANA, a comprehensive enterprise resource planning suite, contains a security flaw in its 'Draft' operation functionality. An authenticated user with restricted permissions can bypass authorization checks to view information they are not supposed to see. While this does not allow an attacker to delete data or crash the system, it results in an unauthorized disclosure of business information.

Technical details

A missing authorization check (CWE-862) exists in the SAP S/4HANA Draft operation component. The vulnerability allows an authenticated user with low privileges to bypass intended access controls and view sensitive data within the entity. The attack vector is network-based and requires basic user authentication but no user interaction. The impact is limited to a loss of confidentiality, as the flaw does not permit unauthorized modification (integrity) or denial of service (availability). SAP has addressed this in SAP Security Note 3515598.

Affected products

  • SAP SE S/4HANA (Draft operation) S4CORE 108

Timeline

  • 2026-07-14: advisory: SAP Security Patch Day release
  • 2026-07-14: disclosed: NVD publication date

References