high2026-08-11SAP BusinessObjectsCVE-2026-66763

Credentials Disclosure in SAP BusinessObjects BI Platform Central Management Server

SAP BusinessObjects BI Platform (Central Management Server)

Our Take

Credential disclosure in the CMS is particularly serious in BO environments because the CMS holds connection credentials to databases, SAP systems, and other data sources. Exposed credentials in the CMS are a lateral movement shortcut. Rotate all managed credentials after patching.

Vulnerability Detail

A credentials disclosure vulnerability in the Central Management Server (CMS) component of SAP BusinessObjects BI Platform exposes sensitive credential material that could allow an authenticated attacker to escalate access or pivot to connected systems and data sources.

Patch Action

Apply SAP Note 3756565. Post-patch, rotate credentials for any CMS-managed connections and data source accounts.

Patch Info

CVSS Score

7.9

SAP Note

3756565

CVE

CVE-2026-66763

Published

2026-08-11

← All patches