CVE-2026-27683: SAP SE SAP Businessobjects Business Intelligence Platform

Medium severity, CVSS 4.1. EPSS: 0.3% chance of exploitation in the next 30 days.

SAP BusinessObjects Business Intelligence application allows an authenticated attacker to inject malicious JavaScript payloads through crafted URLs. When a victim accesses the URL, the script executes in the user�s browser, potentially exposing restricted information. This results in a low impact on confidentiality with no impact on integrity and availability.

Affected products

  • SAP SE SAP Businessobjects Business Intelligence Platform: version 2025 only; version 2027 only

Published 2026-04-14. Last modified 2026-06-17.