Authorization Flaw in SAP S/4HANA OData Service Exposes Data Manipulation Risks
CVE-2026-27676

4.3MEDIUM

What is CVE-2026-27676?

The SAP S/4HANA OData Service suffers from a critical oversight due to missing authorization checks, allowing unauthorized users to manipulate child entities through exposed OData services. This flaw facilitates updating and deleting operations without appropriate permissions, leading to potential data integrity risks. Although the impact on confidentiality and availability remains intact, the integrity concerns necessitate immediate attention to safeguard systems from unauthorized modifications.

Affected Version(s)

SAP S/4HANA OData Service (Manage Technical Object Structures) S4CORE 109

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.