August 11, 2026

CVE Watchtower


← Back to CVE List

CVE-2026-27683NVD

Vulnerability Summary

SAP BusinessObjects Business Intelligence application allows an authenticated attacker to inject malicious JavaScript payloads through crafted URLs. When a victim accesses the URL, the script executes in the user�s browser, potentially exposing restricted information. This results in a low impact on confidentiality with no impact on integrity and availability.
Severity Level
MEDIUM(4.1)
Published Date
Apr 14, 2026
Last Modified
Apr 17, 2026
Exploitation Status
No confirmed exploitation yet
EPSS Score (30-Day)
0.03%Probability
Root Weakness (CWE)
The software does not neutralize user-controllable input before it is placed in output that is used as a web page.
CVSS v3.1 Base Metrics
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredLow
User InteractionRequired
ScopeChanged
ConfidentialityLow
IntegrityNone
AvailabilityNone