CVE-2026-27686

Due to a Missing Authorization Check in SAP Business Warehouse (Service API), an authenticated attacker could perform unauthorized actions via an affected RFC function module. Successful exploitation could enable unauthorized configuration and control changes, potentially disrupting request processing and causing denial of service. This results in low impact on integrity and high impact on availability, while confidentiality remains unaffected.
Configurations

No configuration.

History

10 Mar 2026, 17:38

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-10 17:38

Updated : 2026-03-11 13:53


NVD link : CVE-2026-27686

Mitre link : CVE-2026-27686

CVE.ORG link : CVE-2026-27686


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization