PT-2026-32560 · Sap Se · Sap Business Planning/Consolidation/Sap Business Warehouse
Published
2026-04-14
·
Updated
2026-04-14
·
CVE-2026-27681
CVSS v3.1
9.9
Critical
| AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Due to insufficient authorization checks in SAP Business Planning and Consolidation and SAP Business Warehouse, an authenticated user can execute crafted SQL statements to read, modify, and delete database data. This leads to a high impact on the confidentiality, integrity, and availability of the system.
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sap Business Planning/Consolidation/Sap Business Warehouse