# CVE-2026-23689

## Summary

- **CVE ID:** CVE-2026-23689
- **Severity:** HIGH
- **CVSS Score:** 7.7 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H)
- **CWE:** CWE-606
- **Published:** Feb 10, 2026
- **Last Modified:** Mar 12, 2026

## Description

Due to an uncontrolled resource consumption (Denial of Service) vulnerability, an authenticated attacker with regular user privileges and network access can repeatedly invoke a remote-enabled function module with an excessively large loop-control parameter. This triggers prolonged loop execution that consumes excessive system resources, potentially rendering the system unavailable. Successful exploitation results in a denial-of-service condition that impacts availability, while confidentiality and integrity remain unaffected.

## Affected Products

- SAP_SE — SAP Supply Chain Management (SCMAPO 713)
- SAP_SE — SAP Supply Chain Management (714)
- SAP_SE — SAP Supply Chain Management (SCM 700)
- SAP_SE — SAP Supply Chain Management (701)
- SAP_SE — SAP Supply Chain Management (702)
- SAP_SE — SAP Supply Chain Management (712)

## References

- [CNA](https://me.sap.com/notes/3703092)
- [CNA](https://url.sap/sapsecuritypatchday)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.37%
- **EPSS Percentile:** 30.1

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._