CVE-2026-27686: SAP SE SAP Business Warehouse Service API

Medium severity, CVSS 5.9. EPSS: 0.3% chance of exploitation in the next 30 days.

Due to a Missing Authorization Check in SAP Business Warehouse (Service API), an authenticated attacker could perform unauthorized actions via an affected RFC function module. Successful exploitation could enable unauthorized configuration and control changes, potentially disrupting request processing and causing denial of service. This results in low impact on integrity and high impact on availability, while confidentiality remains unaffected.

Affected products

  • SAP SE SAP Business Warehouse Service API: version 300 only; version 400 only; version 701 only; version 702 only; version 730 only; version 731 only; …

Published 2026-03-10. Last modified 2026-06-17.