CVE-2026-27689
Due to an uncontrolled resource consumption (Denial of Service) vulnerability, an authenticated attacker with regular user privileges and network access can repeatedly invoke a remote-enabled function module with an excessively large loop-control parameter. This triggers prolonged loop execution that consumes excessive system resources, potentially rendering the system unavailable. Successful exploitation results in a denial-of-service condition that impacts availability, while confidentiality and integrity remain unaffected.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.7
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
- EPSS probability
- 0.37%
- CWE
- CWE-606
- Published
- 2026-03-10
- Last modified
- 2026-03-10
Affected products
- SAP_SE SAP Supply Chain Management
- SAP_SE SAP Supply Chain Management
- SAP_SE SAP Supply Chain Management
- SAP_SE SAP Supply Chain Management
- SAP_SE SAP Supply Chain Management
- SAP_SE SAP Supply Chain Management
- SAP_SE SAP Supply Chain Management
- SAP_SE SAP Supply Chain Management
Weakness type
Related vulnerabilities
- CVE-2026-85730 — smol-toml: Denial of Service via malformed TOML documents
- CVE-2026-13761 — Pega Platform versions 7.1.0 through 25.1.2 are affected by an improper validation of inputs that are used for loop conditions, potentially leading to a denial of service or other consequences because of excessive looping.
- CVE-2026-16599 — Denial of Service in GNU wget
- CVE-2026-62901 — .NET Denial of Service Vulnerability
- CVE-2026-71439 — Mermaid radar diagrams are vulnerable to DoS
- CVE-2026-20301 — Cisco IOS Software and IOS XE Software Extensible Messaging Client Protocol Denial of Service Vulnerability
- CVE-2026-67554 — Apache Qpid Proton Dotnet: Unbounded disposition range handling can lead to denial of service
- CVE-2026-68077 — Apache Qpid Broker-J: Unbounded disposition range handling can lead to denial of service