Unrated severityNVD Advisory· Published Mar 10, 2026· Updated Mar 10, 2026
Missing Authorization check in SAP Business Warehouse (Service API)
CVE-2026-27686
Description
Due to a Missing Authorization Check in SAP Business Warehouse (Service API), an authenticated attacker could perform unauthorized actions via an affected RFC function module. Successful exploitation could enable unauthorized configuration and control changes, potentially disrupting request processing and causing denial of service. This results in low impact on integrity and high impact on availability, while confidentiality remains unaffected.
Affected products
1- Range: DW4CORE 200
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.