CVE-2026-24319
SAP Business One vulnerability analysis and mitigation

Overview

CVE-2026-24319 is an information disclosure vulnerability in SAP Business One where sensitive information is written to the application's memory dump files without obfuscation or encryption. Affecting SAP Business One version 10.0 (including the SAP HANA variant), the flaw allows high-privileged local users to extract credentials and other sensitive data from these dump files, potentially enabling unauthorized operations within the B1 environment. It was published on February 10, 2026, with a patch released as part of SAP's February 2026 Security Patch Day. The vulnerability carries a CVSS v3.1 base score of 5.8 (Medium) (Red Hat CVE, SAP Patch Day).

Technical details

The root cause is classified under CWE-316 (Cleartext Storage of Sensitive Information in Memory) and CWE-312 (Cleartext Storage of Sensitive Information): SAP Business One writes sensitive data — such as credentials — to memory dump files without any obfuscation or encryption. Exploitation requires local access to the host system, high privileges, and user interaction (e.g., triggering a memory dump), making the attack vector local with low complexity once access is established. An attacker who can read these dump files can extract plaintext sensitive information directly. No public proof-of-concept or technical write-up detailing specific exploitation mechanics has been identified (Red Hat CVE, Onapsis Blog).

Impact

Successful exploitation results in high confidentiality and integrity impact, with no effect on availability. An attacker with local high-privilege access who obtains the memory dump files could extract sensitive credentials or configuration data, potentially enabling unauthorized modification of company data within the SAP Business One environment. Lateral movement within the B1 environment is a realistic risk if extracted credentials are reused for other SAP services or accounts (Red Hat CVE, SAP Patch Day).

Mitigation and workarounds

SAP has released a patch for this vulnerability as part of the February 2026 Security Patch Day; administrators should apply the relevant SAP Security Note immediately via the SAP Support Portal. As interim mitigations, restrict local system access to SAP Business One 10.0 hosts to trusted administrators only, implement strict access controls on high-privilege accounts, and secure or restrict access to memory dump file directories. Additionally, consider implementing monitoring for unauthorized access to dump file locations and applying encryption controls for sensitive data at rest (SAP Patch Day, Onapsis Blog).

Community reactions

The vulnerability was covered as part of broader SAP February 2026 Patch Day roundups by security firms including Onapsis, SecurityBridge, and RedRays, which noted it among the lower-severity issues addressed that month. Coverage focused primarily on higher-severity vulnerabilities in SAP CRM and SAP S/4HANA patched in the same cycle, with CVE-2026-24319 receiving limited standalone attention due to its medium severity and high exploitation prerequisites (Onapsis Blog, SecurityBridge Blog, RedRays Blog).

Additional resources


SourceThis report was generated using AI

Related SAP Business One vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2023-31403HIGH8
  • SAP Business One logoSAP Business One
  • cpe:2.3:a:sap:business_one
NoYesNov 14, 2023
CVE-2026-24319MEDIUM5.8
  • SAP Business One logoSAP Business One
  • cpe:2.3:a:sap:business_one
NoYesFeb 10, 2026
CVE-2023-39437MEDIUM5.4
  • SAP Business One logoSAP Business One
  • cpe:2.3:a:sap:business_one
NoYesAug 08, 2023
CVE-2023-37487MEDIUM5.3
  • SAP Business One logoSAP Business One
  • cpe:2.3:a:sap:business_one
NoYesAug 08, 2023
CVE-2023-41365MEDIUM4.3
  • SAP Business One logoSAP Business One
  • cpe:2.3:a:sap:business_one
NoYesOct 10, 2023

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management