cbcvebase.
CVE-2026-27675
published 2026-04-14

CVE-2026-27675: SAP Landscape Transformation contains a vulnerability in an RFC-exposed function module that could allow a high privileged adversary to inject arbitrary ABAP…

PriorityP413low2CVSS 3.1
AVNACHPRHUIRSUCNILAN
EPSS
0.17%
6.5th percentile
SAP Landscape Transformation contains a vulnerability in an RFC-exposed function module that could allow a high privileged adversary to inject arbitrary ABAP code and operating system commands. Due to this, some information could be modified, but the attacker does not have control over kind or degree. This leads to a low impact on integrity, while confidentiality and availability are not impacted.

Affected

14 ranges
VendorProductVersion rangeFixed in
sap_sesap_landscape_transformation
sap_sesap_landscape_transformation
sap_sesap_landscape_transformation
sap_sesap_landscape_transformation
sap_sesap_landscape_transformation
sap_sesap_landscape_transformation
sap_sesap_landscape_transformation
sap_sesap_landscape_transformation
sap_sesap_landscape_transformation
sap_sesap_landscape_transformation
sap_sesap_landscape_transformation
sap_sesap_landscape_transformation
sap_sesap_landscape_transformation
sap_sesap_landscape_transformation
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.