CVE-2026-27689
Received Received - Intake
Denial of Service via Resource Exhaustion in SAP Remote Function Module

Publication date: 2026-03-10

Last updated on: 2026-03-10

Assigner: SAP SE

Description
Due to an uncontrolled resource consumption (Denial of Service) vulnerability, an authenticated attacker with regular user privileges and network access can repeatedly invoke a remote-enabled function module with an excessively large loop-control parameter. This triggers prolonged loop execution that consumes excessive system resources, potentially rendering the system unavailable. Successful exploitation results in a denial-of-service condition that impacts availability, while confidentiality and integrity remain unaffected.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-03-10
Last Modified
2026-03-10
Generated
2026-06-16
AI Q&A
2026-03-10
EPSS Evaluated
2026-06-15
NVD
EUVD
Affected Vendors & Products
Currently, no data is known.
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-606 The product does not properly check inputs that are used for loop conditions, potentially leading to a denial of service or other consequences because of excessive looping.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability is an uncontrolled resource consumption issue that allows an authenticated attacker with regular user privileges and network access to repeatedly invoke a remote-enabled function module with an excessively large loop-control parameter.

This causes a prolonged loop execution that consumes excessive system resources, potentially making the system unavailable.

The result is a denial-of-service condition affecting system availability, while confidentiality and integrity are not impacted.

Impact Analysis

The vulnerability can lead to a denial-of-service (DoS) condition by exhausting system resources through prolonged loop execution.

This means the affected system may become unavailable or unresponsive, disrupting normal operations.

However, it does not affect the confidentiality or integrity of the system or its data.

Compliance Impact

I don't know

Detection Guidance

I don't know

Mitigation Strategies

I don't know

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-27689. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart