Sceawere

Vulnerability Detail

CVE-2026-58245UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

SAP Model Mix Planning Hardcoded Credential Vulnerability

Vulnerability Metadata

Severity
Low
Score / CVSS
3.8
Creation Date
4h ago
Vendor
SAP_SE
Product
SAP Advanced Planning and Optimization (Model Mix Planning)
Attack Type
CWE-798: Use of Hard-coded Credentials
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

SAP Advanced Planning and Optimization (Model Mix Planning) contains a hardcoded credential within the source code of the application to perform authorization check to access certain functionalities in the application. An attacker with high privileges could leverage this hardcoded credential to bypass authorization and delete specific planning-related restrictions in the application. Successful exploitation could result in a low impact on confidentiality and integrity, with no impact on availability of the application.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "3.8",
  "pubDate": "2026-08-11T01:17:22.397Z",
  "pubdate": "2026-08-11T01:17:22.397Z",
  "executiveSummary": "SAP Advanced Planning and Optimization (Model Mix Planning) contains a hardcoded credential vulnerability within its application source code.\nThe vulnerability allows an attacker with high privileges to leverage the hardcoded credential to perform unauthorized authorization checks and bypass security controls.\nSuccessful exploitation of this flaw enables an authenticated high-privilege attacker to delete specific planning-related restrictions within the application.\nThe impact resulting from this vulnerability is characterized by a low impact on confidentiality and integrity, with no impact on the overall availability of the affected SAP product.\nPrerequisites for exploitation include possessing high privileges within the application environment to interact with the vulnerable functionality.\nThe risk implications involve potential unauthorized modification or deletion of critical planning restrictions, necessitating immediate remediation by the vendor or system administrators.",
  "technicalDetails": "The root cause of the vulnerability resides in the implementation of the application source code within SAP Advanced Planning and Optimization (Model Mix Planning), where a hardcoded credential is statically embedded to facilitate authorization checks.\nThe vulnerable component is utilized to govern access to specific administrative or functional areas within the Model Mix Planning module.\nBecause the credential is hardcoded directly into the source code rather than being dynamically generated, retrieved securely, or managed via robust session-based access control mechanisms, it introduces a predictable security bypass vector.\nThe attack flow begins when an authenticated user with high privileges targets the specific functionality protected by the flawed authorization check.\nInstead of executing standard role-based or token-based authorization validation, the application evaluates the operation using the embedded hardcoded credential.\nBy leveraging this hardcoded credential, the attacker successfully bypasses the intended authorization boundaries without holding the requisite native permission set normally required for the action.\nUpon bypassing these restrictions, the post-exploitation impact allows the attacker to delete specific planning-related restrictions configured within the system.\nThe exploitation vector requires the attacker to already possess high privileges within the application context, indicating that the vulnerability primarily elevates internal capabilities or simplifies unauthorized administrative deletions.\nNetwork exposure and authentication requirements dictate that the attacker must have network access to the SAP application and valid initial high-privilege access to reach the vulnerable source code execution path.\nNo impact on system availability is observed, limiting the direct operational disruption primarily to data integrity regarding planning restrictions."
}
CVE-2026-58245: SAP Model Mix Planning Hardcoded Credential Vulnerability (LOW Severity, CVSS: 3.8) - Sceawere