Sceawere
Vulnerability Detail
CVE-2026-58245UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
SAP Model Mix Planning Hardcoded Credential Vulnerability
Vulnerability Metadata
- Severity
- Low
- Score / CVSS
- 3.8
- Creation Date
- 4h ago
- Vendor
- SAP_SE
- Product
- SAP Advanced Planning and Optimization (Model Mix Planning)
- Attack Type
- CWE-798: Use of Hard-coded Credentials
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
SAP Advanced Planning and Optimization (Model Mix Planning) contains a hardcoded credential within the source code of the application to perform authorization check to access certain functionalities in the application. An attacker with high privileges could leverage this hardcoded credential to bypass authorization and delete specific planning-related restrictions in the application. Successful exploitation could result in a low impact on confidentiality and integrity, with no impact on availability of the application.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "3.8",
"pubDate": "2026-08-11T01:17:22.397Z",
"pubdate": "2026-08-11T01:17:22.397Z",
"executiveSummary": "SAP Advanced Planning and Optimization (Model Mix Planning) contains a hardcoded credential vulnerability within its application source code.\nThe vulnerability allows an attacker with high privileges to leverage the hardcoded credential to perform unauthorized authorization checks and bypass security controls.\nSuccessful exploitation of this flaw enables an authenticated high-privilege attacker to delete specific planning-related restrictions within the application.\nThe impact resulting from this vulnerability is characterized by a low impact on confidentiality and integrity, with no impact on the overall availability of the affected SAP product.\nPrerequisites for exploitation include possessing high privileges within the application environment to interact with the vulnerable functionality.\nThe risk implications involve potential unauthorized modification or deletion of critical planning restrictions, necessitating immediate remediation by the vendor or system administrators.",
"technicalDetails": "The root cause of the vulnerability resides in the implementation of the application source code within SAP Advanced Planning and Optimization (Model Mix Planning), where a hardcoded credential is statically embedded to facilitate authorization checks.\nThe vulnerable component is utilized to govern access to specific administrative or functional areas within the Model Mix Planning module.\nBecause the credential is hardcoded directly into the source code rather than being dynamically generated, retrieved securely, or managed via robust session-based access control mechanisms, it introduces a predictable security bypass vector.\nThe attack flow begins when an authenticated user with high privileges targets the specific functionality protected by the flawed authorization check.\nInstead of executing standard role-based or token-based authorization validation, the application evaluates the operation using the embedded hardcoded credential.\nBy leveraging this hardcoded credential, the attacker successfully bypasses the intended authorization boundaries without holding the requisite native permission set normally required for the action.\nUpon bypassing these restrictions, the post-exploitation impact allows the attacker to delete specific planning-related restrictions configured within the system.\nThe exploitation vector requires the attacker to already possess high privileges within the application context, indicating that the vulnerability primarily elevates internal capabilities or simplifies unauthorized administrative deletions.\nNetwork exposure and authentication requirements dictate that the attacker must have network access to the SAP application and valid initial high-privilege access to reach the vulnerable source code execution path.\nNo impact on system availability is observed, limiting the direct operational disruption primarily to data integrity regarding planning restrictions."
}