Description
SAP BusinessObjects Business Intelligence Platform (Admin Tools) does not perform sufficient authorization check on certain administrative functionality. An attacker authenticated as a non-administrative user could bypass this restriction to gain limited information about affected functionality. This results in a low impact on confidentiality. There is no impact on integrity and availability.
Published: 2026-08-11
Score: 4.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a missing authorization check in SAP BusinessObjects Business Intelligence Platform (Admin Tools). An authenticated non‑administrative user can bypass restrictions and obtain limited information about certain administrative functionality. The resulting confidentiality impact is low and there is no effect on integrity or availability.

Affected Systems

The affected product is SAP BusinessObjects Business Intelligence Platform (Admin Tools) from SAP SE. No specific version range was disclosed, so all current installations of this component may be susceptible until an official fix is released.

Risk and Exploitability

The CVSS score of 4.3 classifies the flaw as low severity. EPSS data is not available, and it is not listed in CISA KEV. Because the flaw requires authentication, the attack vector is likely remote authenticated, with the attacker needing a user account with limited privileges. The absence of an official patch means the risk remains until a vendor update addresses the issue.

Generated by OpenCVE AI on August 11, 2026 at 01:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any vendor-provided update or patch for SAP BusinessObjects Business Intelligence Platform (Admin Tools) as soon as it becomes available.
  • Review and tighten role assignments, ensuring that only users with legitimate administrative rights can access the affected functions.
  • Enable and monitor audit logs for abnormal or unexpected access attempts to the administrative features, and investigate any deviations promptly.

Generated by OpenCVE AI on August 11, 2026 at 01:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 11 Aug 2026 00:45:00 +0000

Type Values Removed Values Added
Description SAP BusinessObjects Business Intelligence Platform (Admin Tools) does not perform sufficient authorization check on certain administrative functionality. An attacker authenticated as a non-administrative user could bypass this restriction to gain limited information about affected functionality. This results in a low impact on confidentiality. There is no impact on integrity and availability.
Title Missing Authorization Check in SAP BusinessObjects Business Intelligence Platform (Admin Tools)
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published:

Updated: 2026-08-11T00:18:49.428Z

Reserved: 2026-07-27T17:33:56.949Z

Link: CVE-2026-66772

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-11T01:30:04Z

Weaknesses