What is CVE-2026-66763?
This vulnerability in SAP BusinessObjects Business Intelligence Platform arises from storing sensitive user credentials with a hard-coded cryptographic key. An attacker with high privileges and local server access could retrieve these objects and decrypt the stored credentials. Affected systems should apply the official updates provided by SAP to mitigate the risk.
Azərbaycanca: SAP BusinessObjects Business Intelligence Platform-da aşkar edilmiş bu boşluq, istifadəçi obyektləri ilə bağlı həssas etimadnamələrin sərt kodlaşdırılmış (hard-coded) şifrələmə açarı ilə saxlanması səbəbindən yaranır. Yüksək səlahiyyətlərə və serverə lokal girişə malik olan təcavüzkar bu obyektləri əldə edərək saxlanılan məlumatları deşifrə edə bilər. Təsirə məruz qalan sistemlərdə bu konfiqurasiya dəyişdirilməli və SAP tərəfindən təqdim olunan rəsmi yeniləmələr tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-798; shared vendor: SAP
FAQ2
What privileges must an attacker have to exploit CVE-2026-66763 in SAP BusinessObjects Business Intelligence Platform?
The attacker must have high privileges and local server access.
What is the root cause of vulnerability CVE-2026-66763 in SAP BusinessObjects Business Intelligence Platform?
The vulnerability is caused by storing user credentials with a hard-coded cryptographic key.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.