Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-27688

Due to a missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker with user privileges could read Database Analyzer Log Files via a specific RFC function module. The attacker with the necessary privileges to execute this function module could potentially escalate their privileges and read the sensitive data, resulting in a limited impact on the confidentiality of the information stored. However, the integrity and availability of the system are not affected.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 13.5%
CVSS Severity
CVSS v3 Score 5.0
Products affected by CVE-2026-27688


Contact Us

Shodan ® - All rights reserved