Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

CVE-2026-27687: CWE-862: Missing Authorization in SAP_SE SAP S/4HANA HCM Portugal and SAP ERP HCM Portugal

0
Medium
VulnerabilityCVE-2026-27687cvecve-2026-27687cwe-862
Published: Tue Mar 10 2026 (03/10/2026, 00:18:45 UTC)
Source: CVE Database V5
Vendor/Project: SAP_SE
Product: SAP S/4HANA HCM Portugal and SAP ERP HCM Portugal

Description

Due to missing authorization check in SAP S/4HANA HCM Portugal and SAP ERP HCM Portugal, a user with high privileges could access sensitive data belonging to another company. This vulnerability has a high impact on confidentiality and does not affect integrity and availability.

AI-Powered Analysis

AILast updated: 03/10/2026, 01:04:19 UTC

Technical Analysis

CVE-2026-27687 is a vulnerability identified in SAP S/4HANA HCM Portugal and SAP ERP HCM Portugal products, specifically versions S4HCMCPT 100, 101, 102 and SAP_HRCPT 600, 604, 608. The root cause is a missing authorization check (CWE-862), which allows users with high privileges to access sensitive data belonging to other companies within the system. This flaw does not affect data integrity or system availability but has a high impact on confidentiality, potentially exposing sensitive HR-related information across company boundaries. The vulnerability requires network access and high privileges, but no user interaction, and the scope is considered changed (S:C) because it affects multiple tenants or companies within the SAP environment. The CVSS 3.1 vector is AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N, indicating that exploitation requires high privileges and a complex attack vector but results in high confidentiality impact. No public exploits or patches have been reported yet, but the vulnerability is published and should be addressed promptly. This issue is critical for organizations using SAP HCM Portugal modules, especially those managing multiple companies or subsidiaries in a shared SAP environment.

Potential Impact

The primary impact of CVE-2026-27687 is the unauthorized disclosure of sensitive HR data across company boundaries within SAP S/4HANA and ERP HCM Portugal deployments. This can lead to significant confidentiality breaches, exposing employee personal data, payroll information, and other sensitive corporate data. Such exposure can result in regulatory non-compliance, legal liabilities, reputational damage, and loss of trust among employees and business partners. Since the vulnerability requires high privileges, it is mainly a risk if privileged users are compromised or act maliciously. The lack of impact on integrity and availability reduces the risk of data tampering or service disruption but does not diminish the severity of data leakage. Organizations with multi-tenant SAP environments or subsidiaries using these SAP HCM Portugal modules are particularly vulnerable. The medium CVSS score reflects the balance between the high confidentiality impact and the requirement for high privileges and network access.

Mitigation Recommendations

1. Monitor SAP security advisories closely and apply official patches or updates from SAP as soon as they become available to address CVE-2026-27687. 2. Implement strict role-based access control (RBAC) and least privilege principles to limit high-privilege user accounts and regularly review their permissions. 3. Conduct thorough audits of privileged user activities within SAP HCM Portugal modules to detect unauthorized access attempts or anomalous behavior. 4. Segment SAP environments to isolate company data where possible, reducing the risk of cross-company data exposure. 5. Employ SAP-specific security tools and logging to enhance visibility into authorization checks and data access patterns. 6. Train administrators and privileged users on the risks associated with excessive privileges and the importance of adhering to security policies. 7. Consider additional compensating controls such as data masking or encryption for sensitive HR data to minimize exposure in case of unauthorized access. 8. Engage with SAP support or security consultants to validate the security posture of SAP HCM Portugal implementations and ensure compliance with best practices.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
sap
Date Reserved
2026-02-23T17:50:17.028Z
Cvss Version
3.1
State
PUBLISHED

Threat ID: 69af6a8cea502d3aa8e719d5

Added to database: 3/10/2026, 12:49:16 AM

Last enriched: 3/10/2026, 1:04:19 AM

Last updated: 3/13/2026, 11:00:32 PM

Views: 31

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console in Console -> Billing for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses