CVE-2026-27672: SAP SE Material Master Application
Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.
The Material Master application does not enforce authorization checks for authenticated users when executing reports, resulting in the disclosure of sensitive information. This vulnerability has a low impact on confidentiality and does not affect integrity and availability of the system.
Affected products
- SAP SE Material Master Application: version S4CORE 102 only; version 103 only; version 104 only; version 105 only; version 106 only; version 107 only; …
Published 2026-04-14. Last modified 2026-06-17.