Advisory
A note with CVSS 4.3 for component BI-BIP-INV was released by SAP on 11.08.2026. The correction/advisory 3770649 was described with "3770649 - [CVE-2026-66772] Missing Authorization Check in SAP BusinessObjects Business Intelligence Platform (Admin Tools)" and affects the system type BI/BO platform.
A workaround does not exist, according to SAP Security Advisory team. It is advisable to implement the correction as part of maintenance.
The vulnerability addressed is missing authorization check within BI/BO platform.
Missing authority checks are still the most common security defect related to authorizations in custom code. Since SAP uses an explicit authorization model, an authority checks must be coded in order to be executed. If an explicit check is not coded, all users have access. This type of vulnerability not only exists in SAP standard it also exists in customer coding. Check your custom developments for vulnerabilities that pose a risk to your systems. SecurityBridge helps detect code vulnerabilities before they are implemented in production.
Risk specification
SAP BusinessObjects Business Intelligence Platform (Admin Tools) allows an authenticated attacker with non-administrative rights to access administrative functionality, resulting in limited unauthorized access to information about the affected functionality.
Solution
Non-administrative users are now denied access to Admin Tools.
Affected System
SAP BusinessObjects Business Intelligence suite is an analytics platform allowing SAP customers to make better decisions based on their business data. SAP BI is a module meant for producing business insights and expands its power in combination with HANA DB and also exists as BW/4 HANA. Due to processing sensitive business data, the Data security is of utmost importance.
The advisory is valid for
- ENTERPRISE 430 110
- ENTERPRISE 2025 36
