Authorization Flaw in SAP S/4HANA HCM Portugal and SAP ERP HCM Portugal
CVE-2026-27687

5.8MEDIUM

Key Information:

Vendor

SAP

Vendor
CVE Published:
10 March 2026

What is CVE-2026-27687?

A serious authorization flaw exists within SAP S/4HANA HCM Portugal and SAP ERP HCM Portugal, allowing users with elevated privileges to potentially access sensitive data from other organizations. This flaw undermines confidentiality by enabling unauthorized exposure of data, while integrity and availability of the system remain unimpaired. Users are advised to assess their security configurations and apply necessary patches to mitigate risks associated with this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

SAP S/4HANA HCM Portugal and SAP ERP HCM Portugal S4HCMCPT 100

SAP S/4HANA HCM Portugal and SAP ERP HCM Portugal 101

SAP S/4HANA HCM Portugal and SAP ERP HCM Portugal 102

References

CVSS V3.1

Score:
5.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.