CVE-2026-27681: SQL Injection vulnerability in SAP Business Planning and Consolidation and SAP Business Warehouse
Due to insufficient authorization checks in SAP Business Planning and Consolidation and SAP Business Warehouse, an authenticated user can execute crafted SQL statements to read, modify, and delete database data. This leads to a high impact on the confidentiality, integrity, and availability of the system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-27681?
CVE-2026-27681 is rated as a critical severity vulnerability.
How do I fix CVE-2026-27681?
To fix CVE-2026-27681, apply the latest security patches provided by SAP for Business Planning and Consolidation and Business Warehouse.
Who is affected by CVE-2026-27681?
Authenticated users of SAP Business Planning and Consolidation and SAP Business Warehouse are affected by CVE-2026-27681.
What types of attacks can CVE-2026-27681 facilitate?
CVE-2026-27681 can facilitate SQL injection attacks, allowing attackers to read, modify, or delete data.
Is CVE-2026-27681 easy to exploit?
Yes, CVE-2026-27681 can be easily exploited if proper authorization checks are not in place.