CVE-2026-27688: Missing Authorization check in SAP NetWeaver Application Server for ABAP
Due to a missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker with user privileges could read Database Analyzer Log Files via a specific RFC function module. The attacker with the necessary privileges to execute this function module could potentially escalate their privileges and read the sensitive data, resulting in a limited impact on the confidentiality of the information stored. However, the integrity and availability of the system are not affected.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-27688?
CVE-2026-27688 has been classified as a medium severity vulnerability due to the potential exposure of sensitive log files.
How do I fix CVE-2026-27688?
To fix CVE-2026-27688, implement the latest security patches provided by SAP for the NetWeaver Application Server for ABAP.
Who is affected by CVE-2026-27688?
CVE-2026-27688 affects users of SAP NetWeaver Application Server for ABAP that have insufficient authorization checks.
What type of attack is possible with CVE-2026-27688?
An authenticated attacker can exploit CVE-2026-27688 to read sensitive Database Analyzer Log Files.
Is user authentication bypassed in CVE-2026-27688?
No, CVE-2026-27688 requires the attacker to have user privileges for exploitation.