CVE-2026-66772: Missing Authorization Check in SAP BusinessObjects Business Intelligence Platform (Admin Tools)
SAP BusinessObjects Business Intelligence Platform (Admin Tools) does not perform sufficient authorization check on certain administrative functionality. An attacker authenticated as a non-administrative user could bypass this restriction to gain limited information about affected functionality. This results in a low impact on confidentiality. There is no impact on integrity and availability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-66772?
The severity of CVE-2026-66772 is rated medium with a score of 4.3.
What is the risk associated with CVE-2026-66772?
CVE-2026-66772 has a risk rating of 22, indicating a moderately critical vulnerability.
How do I fix CVE-2026-66772?
To fix CVE-2026-66772, apply the latest security patches provided by SAP for the BusinessObjects Business Intelligence Platform.
What impact does CVE-2026-66772 have on SAP BusinessObjects?
CVE-2026-66772 allows an authenticated non-administrative user to bypass authorization checks and access limited functionality.
Who is affected by CVE-2026-66772?
CVE-2026-66772 affects users of the SAP BusinessObjects Business Intelligence Platform, particularly those with non-administrative access.