Sensitive Credential Exposure in SAP BusinessObjects Business Intelligence Platform
CVE-2026-66763

7.9HIGH

What is CVE-2026-66763?

The SAP BusinessObjects Business Intelligence Platform contains a significant vulnerability where sensitive user credentials are stored using a hard-coded cryptographic key. This flaw exposes the credentials to attackers who have high privileges and local access to the server, allowing them to retrieve and decrypt the stored data. Such exploitation could lead to unauthorized access to authentication information and the capability to alter protected data, severely compromising confidentiality and integrity. It is crucial for organizations using this platform to address this vulnerability promptly to safeguard sensitive information.

Affected Version(s)

SAP BusinessObjects Business Intelligence Platform (Central Management Server) ENTERPRISE 430

SAP BusinessObjects Business Intelligence Platform (Central Management Server) 2025

SAP BusinessObjects Business Intelligence Platform (Central Management Server) 2027

References

CVSS V3.1

Score:
7.9
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.