Junglewise Threat Intelligence

CVE-2026-66763: SAP BusinessObjects Business Intelligence Platform insecure credential storage

CVE-2026-66763 · Severity: high · CVSS 7.9 · Published 2026-08-11

Technologies: SAP BusinessObjects Business Intelligence Platform. Vendors: SAP.

Executive brief

SAP BusinessObjects Business Intelligence Platform, used for data analysis and reporting across enterprises, stores sensitive user credentials using a hard-coded encryption key. An attacker with administrative access to the server could decrypt and steal these credentials, potentially gaining unauthorized access to critical business intelligence systems and sensitive data.

Technical details

The vulnerability involves insecure credential storage through use of a hard-coded cryptographic key in SAP BusinessObjects Business Intelligence Platform. An attacker with high privileges and local access to the server can retrieve credential objects and decrypt them using the hard-coded key. Successful exploitation allows an attacker to obtain sensitive authentication data and potentially modify protected information. The attack requires local server access and high privilege level. No patch status is explicitly mentioned in the advisory.

Affected products

  • SAP BusinessObjects Business Intelligence Platform

Timeline

  • 2026-08-11: disclosed

References

Related threats