SAP Security Notes, April 2026

Inprosec through its services, such as the SAP Security Assessment, helps its customers to improve the security levels of their SAP systems.

 

April 2026 Notes

Monthly Summary and Highlights

This month the total number has been 20 notes (19 new and 1 update), 5 more than in March. This month 1 Hot News has been published, one less than in the previous period. Regarding high criticality notes, there is 1, the same amount as in March. Medium and low notes will not be reviewed, so we will provide details on a total of 2 notes (all those with a CVSS of 7 or higher).
We have a total of 20 notes for the whole month (19 are new and 1 is an update of a note from previous months).
We will review in detail a total of 2 notes, all of high criticality and Hot News:
This month the most predominant type has been “Missing Authorization check” (9/20 in the patch day).
In the chart we can see the classification of April’s notes, as well as the evolution and classification of the last 5 previous months (only the notes from Sec. Tuesday / Patch Day – by SAP):

Full details

The complete detail of the most relevant notes is as follows:

Reference links

Other references, from SAP and Onapsis (April):

 

Resources affected

The full list of affected systems/components is as follows:

Did you like it?

Share it on social media!

Leave a Reply

Your email address will not be published. Required fields are marked *

Fill out this field
Fill out this field
Please enter a valid email address.
You need to agree with the terms to proceed

Categories

Calendar of posts

Our services

keyboard_arrow_up