medium2026-08-11SAP BusinessObjectsCVE-2026-66772
Missing Authorization Check in SAP BusinessObjects BI Platform
SAP BusinessObjects BI Platform
Our Take
Third BusinessObjects note this month. BO has three notes — credentials disclosure (7.9), XXE (6.5), and this missing auth (4.3). Plan a BO window.
Vulnerability Detail
A missing authorisation check in the SAP BusinessObjects BI Platform allows an authenticated user to access BI resources or administrative functions beyond their intended permissions.
Patch Action
Apply SAP Note 3770649. Bundle with other BO notes (3756565, 3753141) in a single maintenance window.
Patch Info