CVE-2026-27681 - Vulnerability Analysis
CriticalCVSS: 9.9Last Updated: April 14, 2026
SAP Business Planning and Consolidation & SAP Business Warehouse - SQL Injection
Overview
SAP Business Planning and Consolidation and SAP Business Warehouse contain a SQL injection caused by insufficient authorization checks, letting authenticated users read, modify, and delete database data.
Severity & Score
Impact
Authenticated users can read, modify, and delete database data, impacting confidentiality, integrity, and availability.
Mitigation
Update to the latest available version with authorization checks fixed.
Social Media Activity(4 posts)
š“ CVE-2026-27681 - Critical (9.9) Due to insufficient authorization checks in SAP Business Planning and Consolidation and SAP Business Warehouse, an authenticated user can execute crafted SQL statements to read, modify, and delete database data. This leads to a high impact on the ... š https://www.thehackerwire.com/vulnerability/CVE-2026-27681/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
View original postšØ CRITICAL: CVE-2026-27681 in SAP BPC & BW (CVSS 9.9). Authenticated users can inject SQL, risking data integrity & availability. No patch yet ā restrict access & monitor DB activity. https://radar.offseq.com/threat/cve-2026-27681-cwe-89-improper-neutralization-of-s-a7704991 #OffSeq #SAP #Vuln #SQLi
View original postš“ CVE-2026-27681 - Critical (9.9) Due to insufficient authorization checks in SAP Business Planning and Consolidation and SAP Business Warehouse, an authenticated user can execute crafted SQL statements to read, modify, and delete database data. This leads to a high impact on the ... š https://www.thehackerwire.com/vulnerability/CVE-2026-27681/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
View original postšØ CRITICAL: CVE-2026-27681 in SAP BPC & BW (CVSS 9.9). Authenticated users can inject SQL, risking data integrity & availability. No patch yet ā restrict access & monitor DB activity. https://radar.offseq.com/threat/cve-2026-27681-cwe-89-improper-neutralization-of-s-a7704991 #OffSeq #SAP #Vuln #SQLi
View original postRelated Resources
Details
- CVE ID
- CVE-2026-27681
- Severity
- Critical
- CVSS Score
- 9.9
- Type
- sql_injection
- Status
- new
- EPSS
- 0.0%
- Social Posts
- 4
CWE
- CWE-89
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H