Skip to content
Security Alerts

CVE-2026-27681: Critical SQL Injection Vulnerability in SAP Business Planning and Consolidation and SAP Business Warehouse

Critical SQL Injection vulnerability in SAP Business Planning and Consolidation and SAP Business Warehouse allows data manipulation, service disruption, and potential system compromise. Affects versions HANABPC 810, BPC4HANA 300, SAP_BW 750-758, 816.

Summary

ParameterValue
CVE IDCVE-2026-27681
Alert SourceSAP Security Patch Day - April 2026
CVE Publication Year2026
Date Published2026-04-14
VendorSAP
ProductSAP Business Planning and Consolidation / SAP Business Warehouse
CVSS Score9.9 (Critical)
CISA KEVNo
RansomwareNot confirmed

Vulnerability Description

An SQL Injection vulnerability in SAP Business Planning and Consolidation and SAP Business Warehouse allows attackers to manipulate database queries, potentially leading to unauthorized data access, data modification, denial of service, and full system compromise.

This is one of the most severe vulnerabilities published as part of SAP Security Patch Day in April 2026, with a CVSS score of 9.9 out of 10.

Affected Products and Versions

ProductVersions
SAP Business Planning and Consolidation (HANA)HANABPC 810
SAP BPC for S/4HANABPC4HANA 300
SAP Business WarehouseSAP_BW 750, 752, 753, 754, 755, 756, 757, 758, 816

Required Actions

  1. Immediately apply SAP Security Note 3719353
  2. Review system logs for unusual SQL queries
  3. Restrict network access to BPC/BW components until the patch is applied
  4. Verify user permissions in affected systems

Who Is Affected?

This vulnerability affects organizations using SAP Business Planning and Consolidation and SAP Business Warehouse in the listed versions. Due to the critical nature of this vulnerability (CVSS 9.9), immediate patching is strongly recommended.

Sources


Need help securing your SAP systems? nFlo team offers vulnerability management and 24/7 SOC services. Contact us.

How can nFlo help?

If your organization uses products affected by this vulnerability, contact us. We can help with:

  • Verifying whether your systems are at risk
  • Implementing patches and risk mitigation
  • Monitoring for exploitation attempts in your environment

Useful resources:

Learn More

Share:

Talk to an expert

Have questions about this topic? Get in touch with our specialist.

Sales Representative
Grzegorz Gnych

Grzegorz Gnych

Sales Representative

Response within 24 hours
Free consultation
Individual approach

Providing your phone number will speed up contact.

Want to Reduce IT Risk and Costs?

Book a free consultation - we respond within 24h

Response in 24h Free quote No obligations

Or download free guide:

Download NIS2 Checklist