CVE-2026-27689: Denial of service (DOS) in SAP Supply Chain Management
Due to an uncontrolled resource consumption (Denial of Service) vulnerability, an authenticated attacker with regular user privileges and network access can repeatedly invoke a remote-enabled function module with an excessively large loop-control parameter. This triggers prolonged loop execution that consumes excessive system resources, potentially rendering the system unavailable. Successful exploitation results in a denial-of-service condition that impacts availability, while confidentiality and integrity remain unaffected.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-27689?
CVE-2026-27689 is classified as a Denial of Service vulnerability.
How do I fix CVE-2026-27689?
To mitigate CVE-2026-27689, apply the latest security patches from SAP for Supply Chain Management.
Who can exploit CVE-2026-27689?
CVE-2026-27689 can be exploited by an authenticated attacker with regular user privileges.
What are the implications of CVE-2026-27689?
Exploiting CVE-2026-27689 can lead to uncontrolled resource consumption, resulting in service disruption.
What software is affected by CVE-2026-27689?
CVE-2026-27689 affects SAP Supply Chain Management systems.