Symptom
Users without appropriate permissions can access hire page via a direct URL to the Manage Pending Hire page.
Environment
SAP SuccessFactors Employee Central: Manage Pending Hires
Reproducing the Issue
- Go to Manage Pending Hire page.
- Open an draft (for example: Onboarding) and copy the draft URL.
- Proxy as a user without RBP permissions to access to relevant module.
- Confirm that the draft is not visible in the drafts section for the proxied user.
- Paste the copied draft URL into the browser while still proxied as the user without permissions and hit enter.
- Observe that the draft loads and is accessible despite the lack of RBP permissions.
Cause
This is a Known Issue.
Resolution
- The fix for this issue is planned to be deployed on 1H 2026 release (b2605).
- For release timelines, please review SAP SuccessFactors Product Release & Road Map Information.
See Also
Keywords
rbp bypass, manage pending hire, mph page, unauthorized access, sap successfactors, onboarding draft, direct url access, sensitive information, role-based permissions, regression issue, sap successfactors security, mph ui, column config tool, 1h 2026, 2026, ECT-258285, b2605 , KBA , LOD-SF-EC-INT-UI , MPH UI & Column Config Tool , LOD-SF-EC , Employee Central , LOD-SF-EC-INT , Manage Pending Hires (Integration RCM/ ONB/ OBX + UI) , LOD-SF-OBX , Onboarding 2.0 , LOD-SF-OBX-EC , Integration EC - MPH, Hire , Known Error
SAP Knowledge Base Article - Public