Due to a missing authorization check, SAP S/4HANA (Private Cloud and On-Premise) allows an authenticated user to delete files on the operating system and gain unauthorized control over file operations which could leads to no impact on Confidentiality, Low impact on Integrity and Availability of the application.

Project Subscriptions

No data.

Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 14 Apr 2026 00:15:00 +0000

Type Values Removed Values Added
Description Due to a missing authorization check, SAP S/4HANA (Private Cloud and On-Premise) allows an authenticated user to delete files on the operating system and gain unauthorized control over file operations which could leads to no impact on Confidentiality, Low impact on Integrity and Availability of the application.
Title Missing Authorization Check in SAP S/4HANA (Private Cloud and On-Premise)
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:L'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published:

Updated: 2026-04-14T00:06:38.160Z

Reserved: 2026-02-23T17:50:10.513Z

Link: CVE-2026-27673

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-04-14T00:16:05.477

Modified: 2026-04-14T00:16:05.477

Link: CVE-2026-27673

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses