Due to an uncontrolled resource consumption (Denial of Service) vulnerability, an authenticated attacker with regular user privileges and network access can repeatedly invoke a remote-enabled function module with an excessively large loop-control parameter. This triggers prolonged loop execution that consumes excessive system resources, potentially rendering the system unavailable. Successful exploitation results in a denial-of-service condition that impacts availability, while confidentiality and integrity remain unaffected.
Cite this page
CVE-2026-27689. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2026-27689
Use CWE-606, SAP vendor hub and Awaiting Analysis product page to widen CVE-2026-27689 into its surrounding weakness, vendor, and product context.
Additional editorial context is available in The Weekly Cybersecurity Brief: February 13th, 2026.