SQL Injection Vulnerability in SAP NetWeaver Feedback Notifications Service
CVE-2026-27684
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 10 March 2026
What is CVE-2026-27684?
The SAP NetWeaver Feedback Notifications Service is susceptible to a SQL injection vulnerability that arises from improper handling of user inputs. An authenticated attacker can exploit this flaw by injecting arbitrary SQL commands through input fields directly, as the application fails to validate or escape these inputs before integrating them into SQL queries. This could allow unauthorized access to or modification of database information, thereby posing a significant risk to the application's security posture.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
SAP NetWeaver (Feedback Notification) SAP_ABA 700
SAP NetWeaver (Feedback Notification) 701
SAP NetWeaver (Feedback Notification) 702
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved