A low-privileged SAP user can turn a normal upload feature into database-level theft or tampering. Patching closes the flaw, but it does not undo any SQL already run against BW or BPC data stores.
SAP fixed CVE-2026-27681 in its April 2026 patch day. The bug is a CVSS 9.9 SQL injection in Business Planning and Consolidation and Business Warehouse, and SAP says the vulnerable ABAP program let uploaded files carry arbitrary SQL statements that would execute.
The impact reaches beyond data theft. Attackers could read sensitive financial data, alter reports and consolidation figures, or corrupt database content across BW, BPC, NetWeaver, and Landscape Transformation deployments that expose the affected ABAP path.