Symptom
After upgrading to version 2026.19, customers report that their Data Access Controls (DAC) are no longer working as expected. Specifically:
- Users who previously had access to data based on permission entities are now unable to access that data;
- Permission entities that were working before the upgrade now fail to match users' attributes;
- The issue affects permission entities that use IDP custom attributes (custom1 through custom5) for data row-level security;
- The problem typically manifests when user attributes are defined as arrays in the IDP (e.g.,
['Admin', 'Reader', 'Writer']);
Example Scenario:
- A permission entity was configured with value
' Reader'(with a leading space) - Users with the
Readerattribute could previously access the protected data - After the upgrade, these users can no longer access the data
Read more...
Environment
- SAP Datasphere
Product
SAP Datasphere all versions
Keywords
datasphere, data access control, dac, identity provider attributes, custom schema, multi-value attributes, leading space, array values, attribute-based access control, abac, identity cloud services, operator and values, permissions table, custom application attributes, filtering , KBA , DS-SEC-DAC , Security – Data Access Control , Problem
About this page
This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).Search for additional results
Visit SAP Support Portal's SAP Notes and KBA Search.
SAP Knowledge Base Article - Preview