---
cve: "CVE-2026-27681"
severity: "CRITICAL"
cvss: 9.9
epss: "0.5%"
vendor: "SAP_SE"
kev: false
exploited: false
published: "2026-04-14 00:16:06"
tags: [cve, security, critical]
source: tsecurity.de CVE-Dossier
exported: "2026-09-26T05:51:02+02:00"
---

# CVE-2026-27681

> 9.9 CRITICAL

## Beschreibung

Due to insufficient authorization checks in SAP Business Planning and Consolidation and SAP Business Warehouse, an authenticated user can execute crafted SQL statements to read, modify, and delete database data. This leads to a high impact on the confidentiality, integrity, and availability of the system.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Gering | warn |
| UI Interaktion | Keine | bad |
| S Scope | Verändert | bad |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Hoch | bad |
| A Verfügbarkeit | Hoch | bad |

## Referenzen

- <https://me.sap.com/notes/3719353>
- <https://url.sap/sapsecuritypatchday>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-27681) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
