The SentinelOne Annual Threat Report - A Defenders Guide from the FrontlinesThe SentinelOne Annual Threat ReportGet the Report
Experiencing a Breach?Blog
Get StartedContact Us
SentinelOne
  • Platform
    Platform Overview
    • Singularity Platform
      Welcome to Integrated Enterprise Security
    • AI for Security
      Leading the Way in AI-Powered Security Solutions
    • Securing AI
      Accelerate AI Adoption with Secure AI Tools, Apps, and Agents.
    • How It Works
      The Singularity XDR Difference
    • Singularity Marketplace
      One-Click Integrations to Unlock the Power of XDR
    • Pricing & Packaging
      Comparisons and Guidance at a Glance
    Data & AI
    • Purple AI
      Accelerate SecOps with Generative AI
    • Singularity Hyperautomation
      Easily Automate Security Processes
    • AI-SIEM
      The AI SIEM for the Autonomous SOC
    • AI Data Pipelines
      Security Data Pipeline for AI SIEM and Data Optimization
    • Singularity Data Lake
      AI-Powered, Unified Data Lake
    • Singularity Data Lake for Log Analytics
      Seamlessly Ingest Data from On-Prem, Cloud or Hybrid Environments
    Endpoint Security
    • Singularity Endpoint
      Autonomous Prevention, Detection, and Response
    • Singularity XDR
      Native & Open Protection, Detection, and Response
    • Singularity RemoteOps Forensics
      Orchestrate Forensics at Scale
    • Singularity Threat Intelligence
      Comprehensive Adversary Intelligence
    • Singularity Vulnerability Management
      Application & OS Vulnerability Management
    • Singularity Identity
      Identity Threat Detection and Response
    Cloud Security
    • Singularity Cloud Security
      Block Attacks with an AI-Powered CNAPP
    • Singularity Cloud Native Security
      Secure Cloud and Development Resources
    • Singularity Cloud Workload Security
      Real-Time Cloud Workload Protection Platform
    • Singularity Cloud Data Security
      AI-Powered Threat Detection for Cloud Storage
    • Singularity Cloud Security Posture Management
      Detect and Remediate Cloud Misconfigurations
    Securing AI
    • Prompt Security
      Secure AI Tools Across Your Enterprise
  • Why SentinelOne?
    Why SentinelOne?
    • Why SentinelOne?
      Cybersecurity Built for What’s Next
    • Our Customers
      Trusted by the World’s Leading Enterprises
    • Industry Recognition
      Tested and Proven by the Experts
    • About Us
      The Industry Leader in Autonomous Cybersecurity
    Compare SentinelOne
    • Arctic Wolf
    • Broadcom
    • CrowdStrike
    • Cybereason
    • Microsoft
    • Palo Alto Networks
    • Sophos
    • Splunk
    • Trellix
    • Trend Micro
    • Wiz
    Verticals
    • Energy
    • Federal Government
    • Finance
    • Healthcare
    • Higher Education
    • K-12 Education
    • Manufacturing
    • Retail
    • State and Local Government
  • Services
    Managed Services
    • Managed Services Overview
      Wayfinder Threat Detection & Response
    • Threat Hunting
      World-Class Expertise and Threat Intelligence
    • Managed Detection & Response
      24/7/365 Expert MDR Across Your Entire Environment
    • Incident Readiness & Response
      DFIR, Breach Readiness, & Compromise Assessments
    Support, Deployment, & Health
    • Technical Account Management
      Customer Success with Personalized Service
    • SentinelOne GO
      Guided Onboarding & Deployment Advisory
    • SentinelOne University
      Live and On-Demand Training
    • Services Overview
      Comprehensive Solutions for Seamless Security Operations
    • SentinelOne Community
      Community Login
  • Partners
    Our Network
    • MSSP Partners
      Succeed Faster with SentinelOne
    • Singularity Marketplace
      Extend the Power of S1 Technology
    • Cyber Risk Partners
      Enlist Pro Response and Advisory Teams
    • Technology Alliances
      Integrated, Enterprise-Scale Solutions
    • SentinelOne for AWS
      Hosted in AWS Regions Around the World
    • Channel Partners
      Deliver the Right Solutions, Together
    • SentinelOne for Google Cloud
      Unified, Autonomous Security Giving Defenders the Advantage at Global Scale
    • Partner Locator
      Your Go-to Source for Our Top Partners in Your Region
    Partner Portal→
  • Resources
    Resource Center
    • Case Studies
    • Data Sheets
    • eBooks
    • Reports
    • Videos
    • Webinars
    • Whitepapers
    • Events
    View All Resources→
    Blog
    • Feature Spotlight
    • For CISO/CIO
    • From the Front Lines
    • Identity
    • Cloud
    • macOS
    • SentinelOne Blog
    Blog→
    Tech Resources
    • SentinelLABS
    • Ransomware Anthology
    • Cybersecurity 101
  • About
    About SentinelOne
    • About SentinelOne
      The Industry Leader in Cybersecurity
    • Investor Relations
      Financial Information & Events
    • SentinelLABS
      Threat Research for the Modern Threat Hunter
    • Careers
      The Latest Job Opportunities
    • Press & News
      Company Announcements
    • Cybersecurity Blog
      The Latest Cybersecurity Threats, News, & More
    • FAQ
      Get Answers to Our Most Frequently Asked Questions
    • DataSet
      The Live Data Platform
    • S Foundation
      Securing a Safer Future for All
    • S Ventures
      Investing in the Next Generation of Security, Data and AI
  • Pricing
Get StartedContact Us
CVE Vulnerability Database
Vulnerability Database/CVE-2026-40132

CVE-2026-40132: SAP SEM Authorization Bypass Vulnerability

CVE-2026-40132 is an authorization bypass vulnerability in SAP Strategic Enterprise Management (SEM) Scorecard Wizard. Attackers can access unauthorized data and modify settings to falsify risk assessments. This article covers technical details, affected versions, impact analysis, and mitigation strategies.

Published: May 18, 2026

CVE-2026-40132 Overview

CVE-2026-40132 is a missing authorization vulnerability in SAP Strategic Enterprise Management, specifically within the Scorecard Wizard component of Business Server Pages (BSP). An authenticated attacker can access information they are not authorized to view. The flaw also lets attackers modify default settings and value fields used in risk evaluations. These changes can falsely lower assessed risk levels, undermining the integrity of strategic risk reporting. The weakness is classified as [CWE-862] Missing Authorization and requires network access with low privileges.

Critical Impact

Authenticated attackers can read restricted data and tamper with risk evaluation value fields, producing misleading risk assessments that may influence executive and compliance decisions.

Affected Products

  • SAP Strategic Enterprise Management (SAP SEM)
  • Scorecard Wizard component within Business Server Pages (BSP)
  • Refer to SAP Note #3721959 for the complete list of affected support packages

Discovery Timeline

  • 2026-05-12 - CVE-2026-40132 published to the National Vulnerability Database
  • 2026-05-12 - SAP Security Patch Day advisory published with SAP Note #3721959
  • 2026-05-12 - Last updated in NVD database

Technical Details for CVE-2026-40132

Vulnerability Analysis

The vulnerability resides in the Scorecard Wizard delivered through SAP Business Server Pages within SAP Strategic Enterprise Management. The Scorecard Wizard exposes BSP handlers that fail to enforce authorization checks before serving or modifying scorecard data. Any authenticated user with network access to the BSP application can invoke these handlers and interact with scorecards belonging to other users or organizational units.

Beyond read access, the missing check extends to write operations on value fields and default settings. An attacker can alter the inputs that feed strategic risk calculations. The application then computes risk scores based on tampered values, producing artificially low risk ratings. This affects confidentiality and integrity but does not impact availability.

Root Cause

The root cause is an absent authorization check ([CWE-862]) on Scorecard Wizard request handlers. The BSP application relies on authentication alone and does not validate whether the authenticated principal is permitted to view or modify the targeted scorecard objects and value fields.

Attack Vector

Exploitation requires network access to the SAP BSP endpoint and valid low-privileged credentials. No user interaction is needed. The attacker issues crafted HTTP requests to Scorecard Wizard URLs and supplies identifiers or value parameters for objects outside their assigned scope. The EPSS score is 0.008%, reflecting a low predicted likelihood of opportunistic exploitation, but the risk is elevated in environments where SEM data feeds executive risk reporting.

No public proof-of-concept exploit is available. The vulnerability is described in prose only; refer to the SAP Note #3721959 advisory for component-level technical details.

Detection Methods for CVE-2026-40132

Indicators of Compromise

  • Unexpected HTTP requests to Scorecard Wizard BSP paths from user accounts that do not own the targeted scorecards
  • Audit log entries showing modifications to scorecard value fields or default settings by non-owners
  • Sudden downward shifts in calculated risk ratings without corresponding business activity

Detection Strategies

  • Enable SAP Security Audit Log (SM19/RSAU_CONFIG) for BSP application access and configuration changes in the SEM namespace
  • Correlate BSP HTTP access logs with SEM authorization assignments to identify cross-tenant or cross-unit access attempts
  • Review change documents on scorecard objects for edits performed by accounts lacking the corresponding business role

Monitoring Recommendations

  • Alert on repeated HTTP 200 responses to Scorecard Wizard endpoints originating from low-privileged service or test accounts
  • Baseline normal Scorecard Wizard usage per user and flag deviations in request volume or target object IDs
  • Forward SAP Web Dispatcher and ICM access logs to a centralized SIEM for cross-source correlation

How to Mitigate CVE-2026-40132

Immediate Actions Required

  • Apply the SAP patch referenced in SAP Note #3721959 on all SAP SEM systems
  • Audit recent changes to scorecard value fields and default settings to identify potential tampering
  • Review BSP authorization roles assigned to non-administrative users and remove unnecessary access to the Scorecard Wizard

Patch Information

SAP released the fix as part of the May 2026 SAP Security Patch Day. Implement the corrections delivered in SAP Note #3721959 and consult the SAP Security Patch Day portal for the supported support package levels. Apply patches through standard SAP transport procedures after validation in non-production systems.

Workarounds

  • Restrict network access to the BSP application path hosting the Scorecard Wizard using SAP Web Dispatcher or reverse proxy ACLs
  • Limit the authorization objects required to launch the Scorecard Wizard to a minimal set of named users until patching is complete
  • Disable the Scorecard Wizard BSP service in transaction SICF if it is not actively used
bash
# Configuration example: disable the BSP service via SICF until patching
# Transaction: SICF
# Path: /default_host/sap/bc/bsp/sap/<scorecard_wizard_service>
# Action: Right-click service > Deactivate Service
# Verify with:
#   SE38 > RSICFTREE > filter on service name

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

  • Vulnerability Details
  • TypeAuth Bypass

  • Vendor/TechSap

  • SeverityMEDIUM

  • CVSS Score5.4

  • EPSS Probability0.01%

  • Known ExploitedNo
  • CVSS Vector
  • CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
  • Impact Assessment
  • ConfidentialityLow
  • IntegrityNone
  • AvailabilityNone
  • CWE References
  • CWE-862
  • Technical References
  • SAP Note #3721959

  • SAP Security Patch Day
  • Related CVEs
  • CVE-2026-40134: SAP ICM Authorization Bypass Vulnerability

  • CVE-2026-34261: SAP Business Analytics Auth Bypass Flaw

  • CVE-2026-27686: SAP Business Warehouse Auth Bypass Flaw

  • CVE-2026-0506: SAP ABAP Auth Bypass Vulnerability
Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.

Try SentinelOne
  • Get Started
  • Get a Demo
  • Product Tour
  • Why SentinelOne
  • Pricing & Packaging
  • FAQ
  • Contact
  • Contact Us
  • Customer Support
  • SentinelOne Status
  • Language
  • Platform
  • Singularity Platform
  • Singularity Endpoint
  • Singularity Cloud
  • Singularity AI-SIEM
  • Singularity Identity
  • Singularity Marketplace
  • Purple AI
  • Services
  • Wayfinder TDR
  • SentinelOne GO
  • Technical Account Management
  • Support Services
  • Verticals
  • Energy
  • Federal Government
  • Finance
  • Healthcare
  • Higher Education
  • K-12 Education
  • Manufacturing
  • Retail
  • State and Local Government
  • Cybersecurity for SMB
  • Resources
  • Blog
  • Labs
  • Case Studies
  • Videos
  • Product Tours
  • Events
  • Cybersecurity 101
  • eBooks
  • Webinars
  • Whitepapers
  • Press
  • News
  • Ransomware Anthology
  • Company
  • About Us
  • Our Customers
  • Careers
  • Partners
  • Legal & Compliance
  • Security & Compliance
  • Investor Relations
  • S Foundation
  • S Ventures

©2026 SentinelOne, All Rights Reserved.

Privacy Notice Terms of Use

English