SAP APO Model Mix Planning Hardcoded Credential Bypass
CVE-2026-58245 Published on August 11, 2026
Hard-coded Credentials in SAP Advanced Planning and Optimization (Model Mix Planning)
SAP Advanced Planning and Optimization (Model Mix Planning) contains a hardcoded credential within the source code of the application to perform authorization check to access certain functionalities in the application. An attacker with high privileges could leverage this hardcoded credential to bypass authorization and delete specific planning-related restrictions in the application. Successful exploitation could result in a low impact on confidentiality and integrity, with no impact on availability of the application.
Vulnerability Analysis
CVE-2026-58245 can be exploited with network access, and requires user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a small impact on confidentiality and integrity, and no impact on availability.
Weakness Type
Use of Hard-coded Credentials
The software contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.
Affected Versions
SAP_SE SAP Advanced Planning and Optimization (Model Mix Planning):- Version SCMAPO 713 is affected.
- Version 714 is affected.
- Version S4CORE 102 is affected.
- Version 103 is affected.
- Version 104 is affected.
- Version S4COREOP 104 is affected.
- Version 105 is affected.
- Version 106 is affected.
- Version 107 is affected.
- Version 108 is affected.
- Version 109 is affected.
- Version SCM 700 is affected.
- Version 701 is affected.
- Version 702 is affected.
- Version 712 is affected.