CVE-2026-27681
SQL Injection vulnerability in SAP Business Planning and Consolidation and SAP Business Warehouse
Vexday Risk Score
28Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 9.9EPSS 0.5%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
14 Apr 2026Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Due to insufficient authorization checks in SAP Business Planning and Consolidation and SAP Business Warehouse, an authenticated user can execute crafted SQL statements to read, modify, and delete database data. This leads to a high impact on the confidentiality, integrity, and availability of the system.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →