CVE-2026-27686: Missing Authorization check in SAP Business Warehouse (Service API)
Due to a Missing Authorization Check in SAP Business Warehouse (Service API), an authenticated attacker could perform unauthorized actions via an affected RFC function module. Successful exploitation could enable unauthorized configuration and control changes, potentially disrupting request processing and causing denial of service. This results in low impact on integrity and high impact on availability, while confidentiality remains unaffected.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-27686?
CVE-2026-27686 is considered a high-severity vulnerability due to the potential unauthorized actions it allows within SAP Business Warehouse.
How do I fix CVE-2026-27686?
To fix CVE-2026-27686, apply the latest security patches provided by SAP for the affected SAP Business Warehouse version.
Who is affected by CVE-2026-27686?
CVE-2026-27686 affects customers using SAP Business Warehouse who have not properly implemented authorization checks.
What types of attacks can CVE-2026-27686 enable?
CVE-2026-27686 could enable attackers to perform unauthorized actions and manipulate configurations within the SAP Business Warehouse system.
Is there a workaround for CVE-2026-27686 before applying the patch?
There are no officially recommended workarounds for CVE-2026-27686, so immediate application of the patch is advised.