Junglewise Threat Intelligence

CVE-2026-58245: SAP Advanced Planning and Optimization hardcoded credential in Model Mix Planning

CVE-2026-58245 · Severity: low · CVSS 3.8 · Published 2026-08-11

Vendors: SAP.

Executive brief

SAP Advanced Planning and Optimization (Model Mix Planning) contains a hardcoded credential embedded in the application's source code that can be used to bypass authorization controls. An attacker with high privileges could exploit this credential to delete planning-related restrictions, potentially affecting the integrity of planning data and operations within the system.

Technical details

The vulnerability is a hardcoded credential (weak secret management) embedded in the application source code. The vulnerable component is the authorization check mechanism in Model Mix Planning. The attack requires high privilege access to the system, limiting the attack surface. Exploitation allows an attacker to bypass authorization controls and delete specific planning-related restrictions, resulting in low impact to confidentiality and integrity with no availability impact. The fix is available via SAP Security Notes (SAP Note 3763028) as part of the August 11, 2026 Security Patch Day release.

Affected products

  • SAP Advanced Planning and Optimization <UNKNOWN>

Timeline

  • 2026-08-11: disclosed
  • 2026-08-11: patched: SAP Security Patch Day (note 3763028)

References