HarborGuard / CVE
Back to search
CRITICALCVE-2026-27681Published Modified CNA sap

CVE-2026-27681: SQL Injection vulnerability in SAP Business Planning and Consolidation and SAP Business Warehouse

Due to insufficient authorization checks in SAP Business Planning and Consolidation and SAP Business Warehouse, an authenticated user can execute crafted SQL statements to read, modify, and delete database data. This leads to a high impact on the confidentiality, integrity, and availability of the system.

Metrics

CVSS v3.1
9.9
Severity
CRITICAL
Fixed in
Affected Products
1
Affected packages
  • SAP_SE / SAP Business Planning and Consolidation and SAP Business Warehouse
    HANABPC 810 · BPC4HANA 300 · SAP_BW 750 · 752 · 753 · 754
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVE-2026-27681: SQL Injection vulnerability in SAP Business Planning and Consolidation and SAP Business Warehouse | HarborGuard CVE