CVE-2026-27687: SAP SE SAP s/4hana Hcm Portugal And SAP ERP Hcm Portugal
Medium severity, CVSS 5.8. EPSS: 0.3% chance of exploitation in the next 30 days.
Due to missing authorization check in SAP S/4HANA HCM Portugal and SAP ERP HCM Portugal, a user with high privileges could access sensitive data belonging to another company. This vulnerability has a high impact on confidentiality and does not affect integrity and availability.
Affected products
- SAP SE SAP s/4hana Hcm Portugal And SAP ERP Hcm Portugal: version S4HCMCPT 100 only; version 101 only; version 102 only; version 604 only; version 608 only
Published 2026-03-10. Last modified 2026-06-17.