CVE-2026-27689: SAP SE SAP Supply Chain Management

High severity, CVSS 7.7. EPSS: 0.6% chance of exploitation in the next 30 days.

Due to an uncontrolled resource consumption (Denial of Service) vulnerability, an authenticated attacker with regular user privileges and network access can repeatedly invoke a remote-enabled function module with an excessively large loop-control parameter. This triggers prolonged loop execution that consumes excessive system resources, potentially rendering the system unavailable. Successful exploitation results in a denial-of-service condition that impacts availability, while confidentiality and integrity remain unaffected.

Affected products

  • SAP SE SAP Supply Chain Management: version 714 only; version S4CORE 102 only; version 103 only; version 104 only; version S4COREOP 105 only; version 106 only; …

Published 2026-03-10. Last modified 2026-06-17.