
CVE-2026-27686 Due to a Missing Authorization Check in SAP Business Warehouse (Service API), an authenticated attacker could perform unauthorized actions via an affected RFC functio… https://www.cve.org/CVERecord?id=CVE-2026-27686
Post summary
This is a disclosure of a missing authorization check in SAP Business Warehouse’s Service API that allows authenticated attackers to perform unauthorized actions, though no PoC, exploit code, or patch is detailed.
