CVE Vulnerabilities

CVE-2026-23689

Unchecked Input for Loop Condition

Published: Feb 10, 2026 | Modified: Feb 17, 2026
CVSS 3.x
7.7
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Due to an uncontrolled resource consumption (Denial of Service) vulnerability, an authenticated attacker with regular user privileges and network access can repeatedly invoke a remote-enabled function module with an excessively large loop-control parameter. This triggers prolonged loop execution that consumes excessive system resources, potentially rendering the system unavailable. Successful exploitation results in a denial-of-service condition that impacts availability, while confidentiality and integrity remain unaffected.

Weakness

The product does not properly check inputs that are used for loop conditions, potentially leading to a denial of service or other consequences because of excessive looping.

Affected Software

NameVendorStart VersionEnd Version
Advanced_planning_and_optimizationSap713 (including)713 (including)
Advanced_planning_and_optimizationSap714 (including)714 (including)
Supply_chain_managementSap700 (including)700 (including)
Supply_chain_managementSap701 (including)701 (including)
Supply_chain_managementSap702 (including)702 (including)
Supply_chain_managementSap712 (including)712 (including)

Potential Mitigations

References