CVE-2026-27679 is a missing authorization vulnerability in SAP S/4HANA's frontend OData Service for the Manage Reference Structures module. An attacker with valid credentials could exploit exposed OData services to unauthorized update and delete child entities, compromising data integrity within the system. The vulnerability affects confidentiality and availability minimally, with the primary risk centered on unauthorized data modification. The vulnerability carries a CVSS score of 6.5 (Medium severity) with a network-based attack vector requiring low complexity and low privileges to exploit. While the authorization gap presents a significant integrity risk, the attack requires user authentication and does not provide pathways to compromise confidentiality or system availability. The FAUCET risk score of 35.0/100 indicates moderate organizational risk despite the medium CVSS rating. There are currently no indicators of active exploitation, as the vulnerability is not listed on the Known Exploited Vulnerabilities catalog and remains inactive on security hot lists. The extremely low EPSS score of 0.00029 suggests minimal real-world exploitation activity to date. However, organizations should prioritize patching given the moderate risk profile and the straightforward nature of authorization bypass vulnerabilities, which typically attract attention once disclosure accelerates.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
uis4h_109CPE matchmatch criteria | cpe:2.3:a:sap:manage_reference_structures:uis4h_109:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.