CVE-2026-66763 PUBLISHED

Credentials disclosure in SAP BusinessObjects Business Intelligence Platform (Central Management Server)

Assigner: sap
Reserved: 27.07.2026 Published: 11.08.2026 Updated: 11.08.2026

SAP BusinessObjects Business Intelligence Platform stores certain sensitive credentials associated with user objects using a hard-coded cryptographic key. An attacker with high privileges and local access to the server could retrieve these objects and decrypt the stored credentials. Successful exploitation could allow the attacker to obtain sensitive authentication data and modify protected information, resulting in a high impact on confidentiality and integrity. There is no impact on availability.

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N
CVSS Score: 7.9

Product Status

Vendor SAP_SE
Product SAP BusinessObjects Business Intelligence Platform (Central Management Server)
Versions Default: unaffected
  • Version ENTERPRISE 430 is affected
  • Version 2025 is affected
  • Version 2027 is affected

References

Problem Types