Authorization Flaw in SAP S/4HANA HCM Portugal and SAP ERP HCM Portugal
CVE-2026-27687
5.8MEDIUM
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 10 March 2026
What is CVE-2026-27687?
A serious authorization flaw exists within SAP S/4HANA HCM Portugal and SAP ERP HCM Portugal, allowing users with elevated privileges to potentially access sensitive data from other organizations. This flaw undermines confidentiality by enabling unauthorized exposure of data, while integrity and availability of the system remain unimpaired. Users are advised to assess their security configurations and apply necessary patches to mitigate risks associated with this vulnerability.
Affected Version(s)
SAP S/4HANA HCM Portugal and SAP ERP HCM Portugal S4HCMCPT 100
SAP S/4HANA HCM Portugal and SAP ERP HCM Portugal 101
SAP S/4HANA HCM Portugal and SAP ERP HCM Portugal 102