Credentials disclosure in SAP BusinessObjects Business Intelligence Platform (Central Management Server)
Summary
| CVE | CVE-2026-66763 |
|---|---|
| State | PUBLISHED |
| Assigner | sap |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-11 01:17:23 UTC |
| Updated | 2026-08-11 15:17:33 UTC |
| Description | SAP BusinessObjects Business Intelligence Platform stores certain sensitive credentials associated with user objects using a hard-coded cryptographic key. An attacker with high privileges and local access to the server could retrieve these objects and decrypt the stored credentials. Successful exploitation could allow the attacker to obtain sensitive authentication data and modify protected information, resulting in a high impact on confidentiality and integrity. There is no impact on availability. |
Risk And Classification
Primary CVSS: v3.1 7.9 HIGH from [email protected]
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N
EPSS: 0.001310000 probability, percentile 0.031060000 (date 2026-08-12)
Problem Types: CWE-321 | CWE-321 CWE-321: Use of Hard-coded Cryptographic Key
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 7.9 | HIGH | CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N |
| 3.1 | CNA | CVSS | 7.9 | HIGH | CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N |
CVSS v3.1 Breakdown
Attack Vector
LocalAttack Complexity
LowPrivileges Required
HighUser Interaction
NoneScope
ChangedConfidentiality
HighIntegrity
HighAvailability
NoneCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | SAP SE | SAP BusinessObjects Business Intelligence Platform Central Management Server | affected ENTERPRISE 430 | Not specified |
| CNA | SAP SE | SAP BusinessObjects Business Intelligence Platform Central Management Server | affected 2025 | Not specified |
| CNA | SAP SE | SAP BusinessObjects Business Intelligence Platform Central Management Server | affected 2027 | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| me.sap.com/notes/3756565 | [email protected] | me.sap.com | |
| url.sap/sapsecuritypatchday | [email protected] | url.sap | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.