PT-2026-32557 · Sap · Sap S/4Hana
Published
2026-04-14
·
Updated
2026-04-14
·
CVE-2026-27677
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
SAP S/4HANA (affected versions not specified)
Description
Missing authorization checks in the SAP S/4HANA OData Service (Manage Reference Equipment) allow an attacker to update and delete child entities via OData services without proper authorization. This issue primarily impacts system integrity.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sap S/4Hana