What is CVE-2026-66772?
CVE-2026-66772: Insufficient authorization check in SAP BusinessObjects BI Platform (Admin Tools) may allow an authenticated non-administrative user to bypass restrictions and gain limited information about certain administrative functionality. Affected systems should apply the vendor-provided security patches.
Azərbaycanca: CVE-2026-66772: SAP BusinessObjects BI Platform (Admin Tools) komponentində yetərsiz autorizasiya yoxlaması aşkarlanıb. Qeyri-inzibati istifadəçi autentifikasiya olunaraq müəyyən inzibati funksionallıq haqqında məhdud məlumat əldə edə bilər. Təsirə məruz qalan sistemlərdə vendor tərəfindən təqdim olunan təhlükəsizlik yamalarının tətbiqi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862; shared vendor: SAP
FAQ2
Which component of SAP BusinessObjects BI Platform is affected by CVE-2026-66772?
The CVE-2026-66772 vulnerability is found in the Admin Tools component of SAP BusinessObjects BI Platform.
Is authentication required for a malicious actor to exploit CVE-2026-66772?
Yes, exploitation of CVE-2026-66772 requires the malicious actor to be authenticated as a non-administrative user.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.