PT-2026-32559 · Sap · Sap S/4Hana

Published

2026-04-14

·

Updated

2026-05-04

·

CVE-2026-27679

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions SAP S/4HANA (affected versions not specified)
Description Missing authorization checks in the frontend OData Service (Manage Reference Structures) allow an attacker to update and delete child entities via exposed OData services without proper authorization. This issue primarily impacts integrity.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-27679

Affected Products

Sap S/4Hana