CVE-2026-40134: Missing Authorization Check in SAP Incentive and Commission Management
Due to insufficient authorization checks in the SAP Incentive and Commission Management application, authenticated users could invoke a remote-enabled function module to perform table update operations. This vulnerability has a low impact on integrity with no impact on confidentiality and availability of the application.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-40134?
The severity of CVE-2026-40134 is classified as high due to the potential for unauthorized table update operations.
How do I fix CVE-2026-40134?
To fix CVE-2026-40134, apply the latest security patch provided by SAP for the Incentive and Commission Management application.
What types of users are affected by CVE-2026-40134?
Authenticated users with insufficient authorization checks are affected by CVE-2026-40134.
What can attackers do with CVE-2026-40134?
Attackers can exploit CVE-2026-40134 to invoke remote-enabled functions and perform unauthorized updates to database tables.
When was CVE-2026-40134 publicly disclosed?
CVE-2026-40134 was publicly disclosed in a security announcement from SAP, details of which can be found in security advisories.