CVE-2026-27688

Due to a missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker with user privileges could read Database Analyzer Log Files via a specific RFC function module. The attacker with the necessary privileges to execute this function module could potentially escalate their privileges and read the sensitive data, resulting in a limited impact on the confidentiality of the information stored. However, the integrity and availability of the system are not affected.
Configurations

No configuration.

History

10 Mar 2026, 17:38

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-10 17:38

Updated : 2026-03-10 17:38


NVD link : CVE-2026-27688

Mitre link : CVE-2026-27688

CVE.ORG link : CVE-2026-27688


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization