CVE-2026-27681 PUBLISHED CVSS 9.899999618530273 CRITICAL

CVE-2026-27681 (CVSS 9.9) is caused by insufficient authorization checks, allowing an authenticated user with low privileges to execute arbitrary SQL commands, potentially leading to unauthorised access and data manipulation. This could result in unauthorized access to sensitive database information, modification of critical business data, and potential denial of service through data deletion or manipulation, highly impacting the confidentiality, integrity, and availability of the system. In addition to the critical vulnerability, SAP addressed other high and medium severity vulnerabilities, including: CVE-2026-34256 is a high-severity vulnerability with a CVSS score of 7.1 identified in SAP ERP and SAP S/4 HANA. This flaw impacts both Private Cloud and On-Premises deployments by allowing unauthorised users to perform restricted actions. CVE-2025-64775 is a Denial of Service in BusinessObjects with a CVSS score of 6.5. Exploitation could disrupt critical business analytics and reporting operations. CVE-2026-27674 is a Code Injection in NetWeaver affecting SAP NetWeaver Application Server Java was successfully resolved. CVE-2026-0512 is a Cross-Site Scripting (XSS) vulnerability in SAP Supplier Relationship Management.

Risk Scores

CVSS v3.1
9.899999618530273
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersions
SAPSAP Business Planning and Consolidation
SAPSAP Business Warehouse

Timeline

References

Open in Interactive Console →