Skip to content
SAPCVE-2026-66763

SAP BusinessObjects Business Intelligence Platform (Central : hard-coded key

High7.9CVE-2026-66763 · Published Aug 11, 2026 · updated Aug 26, 2026

SAP BusinessObjects Business Intelligence Platform stores certain sensitive credentials associated with user objects using a hard-coded cryptographic key. An attacker with high privileges and local access to the server could retrieve these objects and decrypt the stored credentials. Successful exploitation could allow the attacker to obtain sensitive authentication data and modify protected information, resulting in a high impact on confidentiality and integrity. There is no impact on availability.

SAP advisory

Affected versions

PackageAffectedFixed in
SAP BusinessObjects Business Intelligence Platform (Central Management Server)
Product
<= ENTERPRISE 430No fix yet
<= 2025No fix yet
<= 2027No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-321

More SAP advisories

All SAP
Advisory
SAP Commerce Cloud (Data Hub Adapter): remote code execution
Critical10.0Aug 11
SAP Business AI Platform (Approuter): improper signature check
Medium5.9Aug 11
SAP Business AI Platform (Approuter): path traversal
Medium5.9Aug 11
SAP Approuter does not sufficiently sanitize certain request headers before...
Medium5.3Aug 11
SAP NetWeaver Application Server ABAP: cross-site scripting
Medium6.3Aug 11
SAP S/4 HANA (Reprocess Bank Statement Items): privilege escalation
Medium4.3Aug 11

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.