CVE-2026-66763
Credentials disclosure in SAP BusinessObjects Business Intelligence Platform (Central Management Server)
CVSS Score
7.9
EPSS Score
0.0%
EPSS Percentile
0th
SAP BusinessObjects Business Intelligence Platform stores certain sensitive credentials associated with user objects using a hard-coded cryptographic key. An attacker with high privileges and local access to the server could retrieve these objects and decrypt the stored credentials. Successful exploitation could allow the attacker to obtain sensitive authentication data and modify protected information, resulting in a high impact on confidentiality and integrity. There is no impact on availability.
| Vendor | sap_se |
| Product | sap businessobjects business intelligence platform (central management server) |
| Published | Aug 11, 2026 |
Stay Ahead of the Next One
Get instant alerts for sap_se sap businessobjects business intelligence platform (central management server)
Be the first to know when new high vulnerabilities affecting sap_se sap businessobjects business intelligence platform (central management server) are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N Attack Vector
Local
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
None
Affected Versions
SAP_SE / SAP BusinessObjects Business Intelligence Platform (Central Management Server)
ENTERPRISE 430 2025 2027