PT-2026-32560 · Sap · Sap Business Planning/Consolidation+1

Published

2026-04-14

·

Updated

2026-05-12

·

CVE-2026-27681

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SAP Business Planning and Consolidation (affected versions not specified) SAP Business Warehouse (affected versions not specified)
Description Insufficient authorization checks in SAP Business Planning and Consolidation and SAP Business Warehouse allow an authenticated user with low privileges to execute crafted SQL statements over the network. This issue occurs because a vulnerable ABAP program allows the upload of files containing arbitrary SQL statements, which are then executed. This can lead to arbitrary database command execution, enabling attackers to read, modify, and delete database data, as well as escalate privileges and move laterally across networks via database compromise. This significantly impacts the confidentiality, integrity, and availability of the system.
Recommendations Apply the updates provided in the April Patch Tuesday release for SAP Business Planning and Consolidation. Apply the updates provided in the April Patch Tuesday release for SAP Business Warehouse.

Fix

RCE

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-05447
CVE-2026-27681

Affected Products

Sap Business Planning/Consolidation
Sap Business Warehouse