CVE-2026-27681
CVSS 9.9 CRITICAL: due to insufficient authorization checks in SAP Business Planning and Consolidation and SAP Business Warehouse, an… EPSS 0.5% (39th percentile).
Vulnerabilities & Exploits · Web App Attack
A low-privileged SAP user can turn a normal upload feature into database-level theft or tampering. Patching closes the flaw, but it does not undo any SQL already run against BW or BPC data stores.
SAP fixed CVE-2026-27681 in its April 2026 patch day. The bug is a CVSS 9.9 SQL injection in Business Planning and Consolidation and Business Warehouse, and SAP says the vulnerable ABAP program let uploaded files carry arbitrary SQL statements that would execute.
The impact reaches beyond data theft. Attackers could read sensitive financial data, alter reports and consolidation figures, or corrupt database content across BW, BPC, NetWeaver, and Landscape Transformation deployments that expose the affected ABAP path.
1 source · Apr 14
CVSS 9.9 CRITICAL: due to insufficient authorization checks in SAP Business Planning and Consolidation and SAP Business Warehouse, an… EPSS 0.5% (39th percentile).
SecurityWeek
SAP Patches Critical ABAP Vulnerability
The company has released 19 new security notes addressing flaws in over a dozen enterprise products.
originalPart of the PlainSec briefing for 2026-04-15
Every edition of this story: SAP ABAP SQL Injection Exposes BW and BPC Data