Vulnerabilities · 154 days ago

SAP ABAP SQL Injection Exposes BW and BPC Data

A low-privileged SAP user can turn a normal upload feature into database-level theft or tampering. Patching closes the flaw, but it does not undo any SQL already run against BW or BPC data stores.

SAP fixed CVE-2026-27681 in its April 2026 patch day. The bug is a CVSS 9.9 SQL injection in Business Planning and Consolidation and Business Warehouse, and SAP says the vulnerable ABAP program let uploaded files carry arbitrary SQL statements that would execute.

The impact reaches beyond data theft. Attackers could read sensitive financial data, alter reports and consolidation figures, or corrupt database content across BW, BPC, NetWeaver, and Landscape Transformation deployments that expose the affected ABAP path.

CVE-2026-27681

NVD KEV

CVSS 9.9 CRITICAL: due to insufficient authorization checks in SAP Business Planning and Consolidation and SAP Business Warehouse, an… EPSS 0.5% (39th percentile).

Timeline

Sources

1 source covering this story

Entities

Part of the PlainSec briefing for 2026-04-15

Editions

Related stories