CRITICALVulnerability
Verified
Global

NVD CRITICAL: CVE-2026-27681 — Due to insufficient authorization checks in SAP Business Planning and Consolidat...

·Source: NIST NVD

Updated:

Executive Summary

Due to insufficient authorization checks in SAP Business Planning and Consolidation and SAP Business Warehouse, an authenticated user can execute crafted SQL statements to read, modify, and delete database data. This leads to a high impact on the confidentiality, integrity, and availability of the system.

Analysis

Due to insufficient authorization checks in SAP Business Planning and Consolidation and SAP Business Warehouse, an authenticated user can execute crafted SQL statements to read, modify, and delete database data. This leads to a high impact on the confidentiality, integrity, and availability of the system. CVSS Score: 9.9. Published: 2026-04-14T00:16:06.560.

Indicators of Compromise (1)

CVE (1)
CVE-2026-27681
Source Attribution

Originally published by NIST NVD on Apr 14, 2026. Verified by: NIST.

Related Threats