Sceawere

Vulnerability Detail

CVE-2026-66763UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

SAP BusinessObjects Hard-Coded Cryptographic Key Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.9
Creation Date
4h ago
Vendor
SAP_SE
Product
SAP BusinessObjects Business Intelligence Platform (Central Management Server)
Attack Type
CWE-321: Use of Hard-coded Cryptographic Key
Vector String
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N
Attack Complexity
LOW

Narrative and Response

Description

SAP BusinessObjects Business Intelligence Platform stores certain sensitive credentials associated with user objects using a hard-coded cryptographic key. An attacker with high privileges and local access to the server could retrieve these objects and decrypt the stored credentials. Successful exploitation could allow the attacker to obtain sensitive authentication data and modify protected information, resulting in a high impact on confidentiality and integrity. There is no impact on availability.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.9",
  "pubDate": "2026-08-11T01:17:23.000Z",
  "pubdate": "2026-08-11T01:17:23.000Z",
  "executiveSummary": "An information disclosure and credential compromise vulnerability exists within the SAP BusinessObjects Business Intelligence Platform related to the management of sensitive cryptographic secrets.\nThe root cause of the vulnerability stems from the utilization of a hard-coded cryptographic key embedded within the application logic to encrypt sensitive credentials associated with user objects.\nSuccessful exploitation of this security flaw allows an authenticated adversary with high privileges and local access to the underlying server to systematically extract these stored user objects and leverage the hard-coded key to successfully decrypt sensitive authentication data.\nThe realization of this attack results in a high impact on both system confidentiality and data integrity, as unauthorized actors can harvest sensitive credentials and subsequently modify protected system information.\nThere is no direct impact on system availability resulting from the exploitation of this specific vulnerability.\nPrerequisites for a successful attack include local server access and possession of high-level administrative privileges within the environment, which significantly restricts the external attack surface but poses a severe internal threat vector or risk from compromised privileged accounts.",
  "technicalDetails": "The vulnerability resides in the credential management subsystem of the SAP BusinessObjects Business Intelligence Platform, specifically within the cryptographic routines responsible for protecting sensitive user credentials.\nThe core architectural defect is the implementation of a static, hard-coded cryptographic key utilized across installations to perform encryption and decryption operations on sensitive authentication artifacts associated with user objects.\nBecause the cryptographic key is hard-coded within the application binaries or configuration components, it can be extracted through reverse engineering or static analysis of the software installation by an unauthorized party possessing local system access.\nThe attack flow proceeds as follows: First, the adversary obtains high-privileged access to the host server hosting the SAP BusinessObjects Business Intelligence Platform, either through legitimate administrative abuse, credential theft, or a separate privilege escalation vector.\nSecond, the attacker locates and accesses the stored user objects and encrypted credential stores residing within the platform's data repositories or file structures.\nThird, utilizing the statically analyzed or extracted hard-coded cryptographic key, the attacker executes decryption algorithms against the retrieved ciphertext.\nFourth, this decryption process yields plaintext sensitive authentication data, such as administrative passwords or integration credentials.\nFinally, armed with this sensitive authentication data, the malicious actor can perform post-exploitation activities, including unauthorized authentication to dependent services, privilege escalation within the platform, and the modification of protected system information, leading to severe compromise of confidentiality and integrity.\nThe vulnerability requires local access and high privileges, meaning network exposure alone is insufficient to trigger the flaw without prior compromise of host-level administrative controls."
}
CVE-2026-66763: SAP BusinessObjects Hard-Coded Cryptographic Key Vulnerability (HIGH Severity, CVSS: 7.9) - Sceawere