PT-2026-32557 · Sap · Sap S/4Hana

Published

2026-04-14

·

Updated

2026-04-14

·

CVE-2026-27677

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions SAP S/4HANA (affected versions not specified)
Description Missing authorization checks in the SAP S/4HANA OData Service (Manage Reference Equipment) allow an attacker to update and delete child entities via OData services without proper authorization. This issue primarily impacts system integrity.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authorization

Weakness Enumeration

Related Identifiers

BDU:2026-05448
CVE-2026-27677

Affected Products

Sap S/4Hana