CVE-2020-26838
CVE-2020-26838 is a critical-severity vulnerability in Sap Business Warehouse with a CVSS 3.x base score of 9.1. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-78.
Key facts
- Severity: Critical (CVSS 3.x base score 9.1)
- CVSS v2: 9.0
- EPSS exploit prediction: 2% (81st percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-78
- Affected product: Sap Business Warehouse
- Published:
- Last modified:
Description
SAP Business Warehouse, versions - 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 782, and SAP BW4HANA, versions - 100, 200 allows an attacker authenticated with (high) developer privileges to submit a crafted request to generate and execute code without requiring any user interaction. It is possible to craft a request which will result in the execution of Operating System commands leading to Code Injection vulnerability which could completely compromise the confidentiality, integrity and availability of the server and any data or other applications running on it.
Frequently asked questions
- What is CVE-2020-26838?
- SAP Business Warehouse, versions - 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 782, and SAP BW4HANA, versions - 100, 200 allows an attacker authenticated with (high) developer privileges to submit a crafted request to generate and execute code without requiring any user interaction. It is possible to craft a request which will result in the execution of Operating System commands leading to Code Injection vulnerability which could completely compromise the confidentiality, integrity and availability of the server and any data or other applications running on it.
- How severe is CVE-2020-26838?
- CVE-2020-26838 has a CVSS 3.x base score of 9.1, rated critical severity. It is exploitable over network with low attack complexity, requires high privileges and no user interaction. Impact on confidentiality is high, integrity high, and availability high.
- Is CVE-2020-26838 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 2% (81st percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2020-26838?
- CVE-2020-26838 primarily affects Sap Business Warehouse. In total, 14 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2020-26838?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its critical severity, prioritise patching exposed systems.
- When was CVE-2020-26838 published?
- CVE-2020-26838 was published on 2020-12-09 and last updated on 2026-06-17.
References
- https://launchpad.support.sap.com/#/notes/2983367
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=564757079
Affected products (14)
- cpe:2.3:a:sap:business_warehouse:700:*:*:*:*:*:*:*
- cpe:2.3:a:sap:business_warehouse:701:*:*:*:*:*:*:*
- cpe:2.3:a:sap:business_warehouse:702:*:*:*:*:*:*:*
- cpe:2.3:a:sap:business_warehouse:731:*:*:*:*:*:*:*
- cpe:2.3:a:sap:business_warehouse:740:*:*:*:*:*:*:*
- cpe:2.3:a:sap:business_warehouse:750:*:*:*:*:*:*:*
- cpe:2.3:a:sap:business_warehouse:751:*:*:*:*:*:*:*
- cpe:2.3:a:sap:business_warehouse:752:*:*:*:*:*:*:*
- cpe:2.3:a:sap:business_warehouse:753:*:*:*:*:*:*:*
- cpe:2.3:a:sap:business_warehouse:754:*:*:*:*:*:*:*
- cpe:2.3:a:sap:business_warehouse:755:*:*:*:*:*:*:*
- cpe:2.3:a:sap:business_warehouse:782:*:*:*:*:*:*:*
- cpe:2.3:a:sap:bw\/4hana:100:*:*:*:*:*:*:*
- cpe:2.3:a:sap:bw\/4hana:200:*:*:*:*:*:*:*
More vulnerabilities in Sap Business Warehouse
- CVE-2021-21465 — Critical (CVSS 9.9): The BW Database Interface allows an attacker with low privileges to execute any crafted database queries, exposing the…
- CVE-2021-21466 — High (CVSS 8.8): SAP Business Warehouse, versions 700, 701, 702, 711, 730, 731, 740, 750, 782 and SAP BW/4HANA, versions 100, 200, allow…
- CVE-2021-21468 — Medium (CVSS 6.5): The BW Database Interface does not perform necessary authorization checks for an authenticated user, resulting in…
- CVE-2024-39594 — Medium (CVSS 6.1): SAP Business Warehouse - Business Planning and Simulation application does not sufficiently encode user controlled…
- CVE-2024-39595 — Medium (CVSS 5.4): SAP Business Warehouse - Business Planning and Simulation application does not sufficiently encode user-controlled…
- CVE-2023-33992 — Medium (CVSS 4.5): The SAP BW BICS communication layer in SAP Business Warehouse and SAP BW/4HANA - version SAP_BW 730, SAP_BW 731, SAP_BW…
All CVEs affecting Sap Business Warehouse →
Other CWE-78 (OS Command Injection) vulnerabilities
- CVE-2026-19188 — Critical (CVSS 10.0): A critical OS command injection vulnerability has been identified in the Haiwell IoT Cloud HMI Gateway product. The…
- CVE-2026-48362 — Critical (CVSS 10.0): ColdFusion is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')…
- CVE-2026-16812 — Critical (CVSS 10.0): VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access…
- CVE-2026-6516 — Critical (CVSS 10.0): Zohocorp ManageEngine ADAudit Plus versions before 8606 are affected by Unauthenticated Remote code execution due to…
- CVE-2026-46339 — Critical (CVSS 10.0): 9Router is an AI router & token saver. From 0.4.30 until 0.4.37, 9Router's src/proxy.js middleware did not protect…
- CVE-2026-59726 — Critical (CVSS 10.0): Ruflo is an agent meta-harness for Claude Code and Codex. Prior to 3.16.3, ruflo's default docker-compose deployment…