
CVE-2026-66763: SAP BusinessObjects CMS encrypts stored credentials with a hardcoded cryptographic key baked into the source code. Same key ships with every installation. Anyone with local server access can decrypt every stored password. Fix: Apply SAP Note 3594149, then rotate every credential. https://hol.org/blog/cve-2026-66763-sap-businessobjects-cms-hardcoded-crypto-key
Post summary
A hardcoded key vulnerability in SAP BusinessObjects CMS is disclosed with an available patch (SAP Note 3594149); applying the note and rotating credentials mitigates the risk.

