medium2026-08-11SAP BusinessObjectsCVE-2026-66772

Missing Authorization Check in SAP BusinessObjects BI Platform

SAP BusinessObjects BI Platform

Our Take

Third BusinessObjects note this month. BO has three notes — credentials disclosure (7.9), XXE (6.5), and this missing auth (4.3). Plan a BO window.

Vulnerability Detail

A missing authorisation check in the SAP BusinessObjects BI Platform allows an authenticated user to access BI resources or administrative functions beyond their intended permissions.

Patch Action

Apply SAP Note 3770649. Bundle with other BO notes (3756565, 3753141) in a single maintenance window.

Patch Info

CVSS Score

4.3

SAP Note

3770649

CVE

CVE-2026-66772

Published

2026-08-11

← All patches