Ad

CVE-2026-27673

MEDIUM CVSS 3.1: 4.9 EPSS 0.03%
Updated Apr 17, 2026
SAP
Parameter Value
CVSS 4.9 (MEDIUM)
Type CWE-862 (Missing Authorization)
Vendor SAP
Public PoC No

Due to a missing authorization check, SAP S/4HANA (Private Cloud and On-Premise) allows an authenticated user to delete files on the operating system and gain unauthorized control over file operations which could leads to no impact on Confidentiality, Low impact on Integrity and Availability of the application.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
High
Difficult to exploit
Privileges Required
Low
Basic privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
None
No data leak
Integrity
Low
Partial data modification
Availability
Low
Partial disruption

CVSS Vector v3.1