high2026-08-11SAP BusinessObjectsCVE-2026-66763
Credentials Disclosure in SAP BusinessObjects BI Platform Central Management Server
SAP BusinessObjects BI Platform (Central Management Server)
Our Take
Credential disclosure in the CMS is particularly serious in BO environments because the CMS holds connection credentials to databases, SAP systems, and other data sources. Exposed credentials in the CMS are a lateral movement shortcut. Rotate all managed credentials after patching.
Vulnerability Detail
A credentials disclosure vulnerability in the Central Management Server (CMS) component of SAP BusinessObjects BI Platform exposes sensitive credential material that could allow an authenticated attacker to escalate access or pivot to connected systems and data sources.
Patch Action
Apply SAP Note 3756565. Post-patch, rotate credentials for any CMS-managed connections and data source accounts.
Patch Info