A Leader in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection. Six years running.Six years. Gartner® Magic Quadrant™ Leader.Find Out Why
Experiencing a Breach?Blog
Get StartedContact Us
SentinelOne
  • Platform
    Platform Overview
    • Singularity Platform
      Welcome to Integrated Enterprise Security
    • AI for Security
      Leading the Way in AI-Powered Security Solutions
    • Securing AI
      Accelerate AI Adoption with Secure AI Tools, Apps, and Agents.
    • How It Works
      The Singularity XDR Difference
    • Singularity Marketplace
      One-Click Integrations to Unlock the Power of XDR
    • Pricing & Packaging
      Comparisons and Guidance at a Glance
    Data & AI
    • Purple AI
      Accelerate SecOps with Generative AI
    • Singularity Hyperautomation
      Easily Automate Security Processes
    • AI-SIEM
      The AI SIEM for the Autonomous SOC
    • AI Data Pipelines
      Security Data Pipeline for AI SIEM and Data Optimization
    • Singularity Data Lake
      AI-Powered, Unified Data Lake
    • Singularity Data Lake for Log Analytics
      Seamlessly Ingest Data from On-Prem, Cloud or Hybrid Environments
    Endpoint Security
    • Singularity Endpoint
      Autonomous Prevention, Detection, and Response
    • Singularity XDR
      Native & Open Protection, Detection, and Response
    • Singularity RemoteOps Forensics
      Orchestrate Forensics at Scale
    • Singularity Threat Intelligence
      Comprehensive Adversary Intelligence
    • Singularity Vulnerability Management
      Application & OS Vulnerability Management
    • Singularity Identity
      Identity Threat Detection and Response
    Cloud Security
    • Singularity Cloud Security
      Block Attacks with an AI-Powered CNAPP
    • Singularity Cloud Native Security
      Secure Cloud and Development Resources
    • Singularity Cloud Workload Security
      Real-Time Cloud Workload Protection Platform
    • Singularity Cloud Data Security
      AI-Powered Threat Detection for Cloud Storage
    • Singularity Cloud Security Posture Management
      Detect and Remediate Cloud Misconfigurations
    Securing AI
    • Prompt Security
      Secure AI Tools Across Your Enterprise
  • Why SentinelOne?
    Why SentinelOne?
    • Why SentinelOne?
      Cybersecurity Built for What’s Next
    • Our Customers
      Trusted by the World’s Leading Enterprises
    • Industry Recognition
      Tested and Proven by the Experts
    • About Us
      The Industry Leader in Autonomous Cybersecurity
    Compare SentinelOne
    • Arctic Wolf
    • Broadcom
    • CrowdStrike
    • Cybereason
    • Microsoft
    • Palo Alto Networks
    • Sophos
    • Splunk
    • Trellix
    • Trend Micro
    • Wiz
    Verticals
    • Energy
    • Federal Government
    • Finance
    • Healthcare
    • Higher Education
    • K-12 Education
    • Manufacturing
    • Retail
    • State and Local Government
  • Services
    Managed Services
    • Managed Services Overview
      Wayfinder Threat Detection & Response
    • Threat Hunting
      World-Class Expertise and Threat Intelligence
    • Managed Detection & Response
      24/7/365 Expert MDR Across Your Entire Environment
    • Incident Readiness & Response
      DFIR, Breach Readiness, & Compromise Assessments
    Support, Deployment, & Health
    • Technical Account Management
      Customer Success with Personalized Service
    • SentinelOne GO
      Guided Onboarding & Deployment Advisory
    • SentinelOne University
      Live and On-Demand Training
    • Services Overview
      Comprehensive Solutions for Seamless Security Operations
    • SentinelOne Community
      Community Login
  • Partners
    Our Network
    • MSSP Partners
      Succeed Faster with SentinelOne
    • Singularity Marketplace
      Extend the Power of S1 Technology
    • Cyber Risk Partners
      Enlist Pro Response and Advisory Teams
    • Technology Alliances
      Integrated, Enterprise-Scale Solutions
    • SentinelOne for AWS
      Hosted in AWS Regions Around the World
    • Channel Partners
      Deliver the Right Solutions, Together
    • SentinelOne for Google Cloud
      Unified, Autonomous Security Giving Defenders the Advantage at Global Scale
    • Partner Locator
      Your Go-to Source for Our Top Partners in Your Region
    Partner Portal→
  • Resources
    Resource Center
    • Case Studies
    • Data Sheets
    • eBooks
    • Reports
    • Videos
    • Webinars
    • Whitepapers
    • Events
    View All Resources→
    Blog
    • Feature Spotlight
    • For CISO/CIO
    • From the Front Lines
    • Identity
    • Cloud
    • macOS
    • SentinelOne Blog
    Blog→
    Tech Resources
    • SentinelLABS
    • Ransomware Anthology
    • Cybersecurity 101
  • About
    About SentinelOne
    • About SentinelOne
      The Industry Leader in Cybersecurity
    • Investor Relations
      Financial Information & Events
    • SentinelLABS
      Threat Research for the Modern Threat Hunter
    • Careers
      The Latest Job Opportunities
    • Press & News
      Company Announcements
    • Cybersecurity Blog
      The Latest Cybersecurity Threats, News, & More
    • FAQ
      Get Answers to Our Most Frequently Asked Questions
    • DataSet
      The Live Data Platform
    • S Foundation
      Securing a Safer Future for All
    • S Ventures
      Investing in the Next Generation of Security, Data and AI
  • Pricing
Get StartedContact Us
CVE Vulnerability Database
Vulnerability Database/CVE-2026-44750

CVE-2026-44750: SAP MDG Privilege Escalation Vulnerability

CVE-2026-44750 is a privilege escalation flaw in SAP MDG Review Match Groups Application that lets low-privileged users bypass authorization checks. This post covers the technical details, affected versions, and mitigation.

Published: June 11, 2026

CVE-2026-44750 Overview

CVE-2026-44750 is a missing authorization check vulnerability in the SAP Master Data Governance (MDG) Review Match Groups Application. The application fails to enforce authorization checks for authenticated users, allowing a low-privileged user to perform actions that would otherwise be restricted. Successful exploitation results in privilege escalation with a low impact on integrity. Confidentiality and availability are not affected. The flaw is classified under CWE-862: Missing Authorization.

Critical Impact

Authenticated low-privileged users can perform restricted actions in the SAP MDG Review Match Groups Application, leading to privilege escalation with limited integrity impact.

Affected Products

  • SAP Master Data Governance (MDG)
  • SAP MDG Review Match Groups Application
  • Refer to SAP Note #3673181 for the complete list of affected SAP MDG versions

Discovery Timeline

  • 2026-06-09 - CVE-2026-44750 published to the National Vulnerability Database
  • 2026-06-09 - Last updated in NVD database

Technical Details for CVE-2026-44750

Vulnerability Analysis

The vulnerability resides in the Review Match Groups Application within SAP Master Data Governance. SAP MDG centralizes the governance of master data such as business partners, materials, and financial entities across SAP landscapes. The Review Match Groups Application supports the review and reconciliation of duplicate or matched data records during governance workflows.

The application does not validate whether the authenticated user holds the authorization objects required to perform certain operations. As a result, any authenticated user with low privileges can invoke functionality intended for users with higher authorization levels. The flaw is a server-side authorization enforcement gap, not a client-side restriction that could be bypassed by interface manipulation alone.

The impact is limited to integrity. Attackers cannot read sensitive data they were not already entitled to view, and they cannot disrupt availability. They can, however, modify master data review outcomes in ways that should require elevated privileges.

Root Cause

The root cause is a missing authorization check [CWE-862]. SAP ABAP applications rely on explicit AUTHORITY-CHECK statements to validate that a user has the required authorization objects before executing privileged actions. In the affected component, one or more of these checks are absent from the code path serving the Review Match Groups Application functions.

Attack Vector

Exploitation requires network access to the SAP MDG application and a valid authenticated session with low privileges. No user interaction is required beyond the attacker submitting crafted requests. The attacker authenticates with existing low-privileged credentials, navigates to or directly invokes the Review Match Groups Application function, and triggers actions that should be gated by authorization checks. Because the server does not enforce those checks, the actions complete successfully and the user effectively escalates privileges within the MDG workflow.

No verified exploit code or public proof-of-concept is available at the time of publication. See the SAP Security Patch Day advisory for vendor guidance.

Detection Methods for CVE-2026-44750

Indicators of Compromise

  • Audit log entries showing low-privileged users invoking Review Match Groups Application transactions or function modules they have not historically used.
  • Successful modification of match group review outcomes performed by user accounts lacking the expected MDG governance roles.
  • Unexpected sequences of MDG workflow state changes initiated from non-administrative user sessions.

Detection Strategies

  • Enable and review the SAP Security Audit Log (SM19/SM20) for transactions and RFC calls related to the MDG Review Match Groups Application.
  • Correlate user role assignments against the activities performed in MDG to identify activity inconsistent with assigned authorization profiles.
  • Use SAP UI logging and Read Access Logging (RAL) where applicable to capture access patterns to the affected application.

Monitoring Recommendations

  • Ingest SAP audit and change document logs into a centralized SIEM and alert on privilege-sensitive MDG operations performed by non-privileged accounts.
  • Baseline normal usage of the Review Match Groups Application per user role and alert on deviations.
  • Monitor SAP change documents for unauthorized modifications to master data review decisions.

How to Mitigate CVE-2026-44750

Immediate Actions Required

  • Apply the SAP-provided patch referenced in SAP Note #3673181 as soon as it can be tested and deployed.
  • Review user assignments for MDG roles and remove unnecessary access to the Review Match Groups Application.
  • Audit recent activity in MDG match group reviews to identify any unauthorized changes prior to patching.

Patch Information

SAP released the fix as part of the SAP Security Patch Day program. Customers should consult SAP Note #3673181 for the exact support package and patch level required for their SAP MDG release. Additional advisories are available on the SAP Security Patch Day portal.

Workarounds

  • Restrict access to the Review Match Groups Application to users who explicitly require it through tightened authorization profile assignments.
  • Implement compensating controls in custom MDG workflows that revalidate user authorizations before committing review decisions.
  • Increase audit log retention and review frequency for MDG transactions until the patch is deployed.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

  • Vulnerability Details
  • TypePrivilege Escalation

  • Vendor/TechSap

  • SeverityMEDIUM

  • CVSS Score4.3

  • EPSS Probability0.03%

  • Known ExploitedNo
  • CVSS Vector
  • CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
  • Impact Assessment
  • ConfidentialityLow
  • IntegrityNone
  • AvailabilityNone
  • CWE References
  • CWE-862
  • Technical References
  • SAP Note #3673181

  • SAP Security Patch Day
  • Related CVEs
  • CVE-2025-42953: SAP NetWeaver Privilege Escalation Flaw

  • CVE-2025-42983: SAP Business Warehouse Privilege Escalation

  • CVE-2026-34256: SAP ERP Privilege Escalation Vulnerability

  • CVE-2026-23688: SAP Fiori Privilege Escalation Flaw
Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.

Try SentinelOne
  • Get Started
  • Get a Demo
  • Product Tour
  • Why SentinelOne
  • Pricing & Packaging
  • FAQ
  • Contact
  • Contact Us
  • Customer Support
  • SentinelOne Status
  • Language
  • Platform
  • Singularity Platform
  • Singularity Endpoint
  • Singularity Cloud
  • Singularity AI-SIEM
  • Singularity Identity
  • Singularity Marketplace
  • Purple AI
  • Services
  • Wayfinder TDR
  • SentinelOne GO
  • Technical Account Management
  • Support Services
  • Verticals
  • Energy
  • Federal Government
  • Finance
  • Healthcare
  • Higher Education
  • K-12 Education
  • Manufacturing
  • Retail
  • State and Local Government
  • Cybersecurity for SMB
  • Resources
  • Blog
  • Labs
  • Case Studies
  • Videos
  • Product Tours
  • Events
  • Cybersecurity 101
  • eBooks
  • Webinars
  • Whitepapers
  • Press
  • News
  • Ransomware Anthology
  • Company
  • About Us
  • Our Customers
  • Careers
  • Partners
  • Legal & Compliance
  • Security & Compliance
  • Investor Relations
  • S Foundation
  • S Ventures

©2026 SentinelOne, All Rights Reserved.

Privacy Notice Terms of Use

English