me.sap.com
https://me.sap.com/notes/3719502 CVE-2026-27689
HIGH
Denial of service (DOS) in SAP Supply Chain Management
Record summary
CVE-2026-27689 has a selected CVSS score of 7.7 (high).
Description
Due to an uncontrolled resource consumption (Denial of Service) vulnerability, an authenticated attacker with regular user privileges and network access can repeatedly invoke a remote-enabled function module with an excessively large loop-control parameter. This triggers prolonged loop execution that consumes excessive system resources, potentially rendering the system unavailable. Successful exploitation results in a denial-of-service condition that impacts availability, while confidentiality and integrity remain unaffected.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 10, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
SAP Supply Chain ManagementBrowse SAP_SE / SAP Supply Chain ManagementDefault status: unaffected | CVE List | SCMAPO 713 | affected |
| 714 | affected | ||
| S4CORE 102 | affected | ||
| 103 | affected | ||
| 104 | affected | ||
| S4COREOP 105 | affected | ||
| 106 | affected | ||
| 107 | affected | ||
| 108 | affected | ||
| 109 | affected | ||
| SCM 700 | affected | ||
| 701 | affected | ||
| Showing 12 of 14 version ranges | |||
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-27689 url.sap
https://url.sap/sapsecuritypatchday