CVE-2026-27681
CVSS 9.9 CRITICAL: due to insufficient authorization checks in SAP Business Planning and Consolidation and SAP Business Warehouse, an… EPSS 0.5% (39th percentile).
Vulnerabilities · 154 days ago
A low-privileged SAP user can turn a normal upload feature into database-level theft or tampering. Patching closes the flaw, but it does not undo any SQL already run against BW or BPC data stores.
SAP fixed CVE-2026-27681 in its April 2026 patch day. The bug is a CVSS 9.9 SQL injection in Business Planning and Consolidation and Business Warehouse, and SAP says the vulnerable ABAP program let uploaded files carry arbitrary SQL statements that would execute.
The impact reaches beyond data theft. Attackers could read sensitive financial data, alter reports and consolidation figures, or corrupt database content across BW, BPC, NetWeaver, and Landscape Transformation deployments that expose the affected ABAP path.
CVSS 9.9 CRITICAL: due to insufficient authorization checks in SAP Business Planning and Consolidation and SAP Business Warehouse, an… EPSS 0.5% (39th percentile).
1 source covering this story
SAP Patches Critical ABAP Vulnerability
The company has released 19 new security notes addressing flaws in over a dozen enterprise products.
Part of the PlainSec briefing for 2026-04-15