Home

Description

Due to a missing authorization check, SAP S/4HANA (Private Cloud and On-Premise) allows an authenticated user to delete files on the operating system and gain unauthorized control over file operations which could leads to no impact on Confidentiality, Low impact on Integrity and Availability of the application.

PUBLISHED Reserved 2026-02-23 | Published 2026-04-14 | Updated 2026-04-14 | Assigner sap




MEDIUM: 4.9CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:L

Problem types

CWE-862: Missing Authorization

Product status

Default status
unaffected

S4CORE 105
affected

106
affected

107
affected

108
affected

109
affected

FI-CA 606
affected

616
affected

617
affected

618
affected

References

me.sap.com/notes/3703813

url.sap/sapsecuritypatchday

cve.org (CVE-2026-27673)

nvd.nist.gov (CVE-2026-27673)

Download JSON