PT-2026-32560 · Sap · Sap Business Planning/Consolidation+1
Published
2026-04-14
·
Updated
2026-05-12
·
CVE-2026-27681
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SAP Business Planning and Consolidation (affected versions not specified)
SAP Business Warehouse (affected versions not specified)
Description
Insufficient authorization checks in SAP Business Planning and Consolidation and SAP Business Warehouse allow an authenticated user with low privileges to execute crafted SQL statements over the network. This issue occurs because a vulnerable ABAP program allows the upload of files containing arbitrary SQL statements, which are then executed. This can lead to arbitrary database command execution, enabling attackers to read, modify, and delete database data, as well as escalate privileges and move laterally across networks via database compromise. This significantly impacts the confidentiality, integrity, and availability of the system.
Recommendations
Apply the updates provided in the April Patch Tuesday release for SAP Business Planning and Consolidation.
Apply the updates provided in the April Patch Tuesday release for SAP Business Warehouse.
Fix
RCE
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sap Business Planning/Consolidation
Sap Business Warehouse