Cyber Posture

CVE-2026-0485

High

Published: 10 February 2026

Published
10 February 2026
Modified
17 February 2026
KEV Added
Patch
CVSS Score 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score 0.0006 19.5th percentile
Risk Priority 15 60% EPSS · 20% KEV · 20% CVSS

Summary

CVE-2026-0485 is a high-severity Amplification (CWE-405) vulnerability in Sap Businessobjects Business Intelligence Platform. Its CVSS base score is 7.5 (High).

Operationally, exploitation aligns with the MITRE ATT&CK technique Exploit Public-Facing Application (T1190); ranked at the 19.5th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

Threat & Defense at a Glance

What attackers do: exploitation maps to Exploit Public-Facing Application (T1190) and 1 other technique.
Threat & Defense Details

Likely Mitigating ControlsAI

Per-CVE control mapping for this CVE has not run yet; the list below is derived from the weakness types (CWEs) cited in the NVD entry.

addresses: CWE-405

Reduces impact of amplification attacks that overwhelm the primary site by allowing operations to shift to an equivalent alternate site.

addresses: CWE-405

Alternate services reduce the impact of amplification attacks that exhaust primary telecommunications resources.

addresses: CWE-405

Amplification attacks that exhaust the primary path are mitigated by the existence of an independent alternate path for command traffic.

addresses: CWE-405

Employs controls that mitigate amplification attacks causing asymmetric resource use.

addresses: CWE-405

Limits amplification effects by controlling how resources are allocated under high-volume or recursive load.

MITRE ATT&CK Enterprise TechniquesAI

T1190 Exploit Public-Facing Application Initial Access
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.
T1499.004 Application or System Exploitation Impact
Adversaries may exploit software vulnerabilities that can cause an application or system to crash and deny availability to users.
Why these techniques?

Remote unauthenticated crash of public-facing CMS directly enables T1190 (exploit public-facing app) for initial access and T1499.004 (application/system exploitation) for repeated DoS via crash/restart loops.

Confidence: HIGH · MITRE ATT&CK Enterprise v18.1

NVD Description

SAP BusinessObjects BI Platform allows an unauthenticated attacker to send specially crafted requests that could cause the Content Management Server (CMS) to crash and automatically restart. By repeatedly submitting these requests, the attacker could induce a persistent service disruption, rendering…

more

the CMS completely unavailable. Successful exploitation results in a high impact on availability, while confidentiality and integrity remain unaffected.

Deeper analysisAI

CVE-2026-0485 is a vulnerability in the SAP BusinessObjects BI Platform that affects the Content Management Server (CMS). It enables an unauthenticated attacker to send specially crafted requests, causing the CMS to crash and automatically restart. Repeated exploitation leads to persistent service disruption, making the CMS completely unavailable and resulting in high impact on availability, with no effects on confidentiality or integrity. The issue is associated with CWE-405 and has a CVSS v3.1 base score of 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).

An unauthenticated attacker with network access can exploit this vulnerability remotely, requiring low complexity and no user interaction or privileges. Successful attacks allow the attacker to crash the CMS repeatedly, inducing a denial-of-service condition that renders the service unavailable.

SAP provides mitigation guidance in its security advisories, including a dedicated security note at https://me.sap.com/notes/3678282 and details on the SAP Security Patch Day at https://url.sap/sapsecuritypatchday.

Details

CWE(s)

Affected Products

sap
businessobjects business intelligence platform
2025, 2027, 430

CVEs Like This One

CVE-2026-0490Same product: Sap Businessobjects Business Intelligence Platform
CVE-2026-0508Same product: Sap Businessobjects Business Intelligence Platform
CVE-2025-0061Same product: Sap Businessobjects Business Intelligence Platform
CVE-2025-0064Same product: Sap Businessobjects Business Intelligence Platform
CVE-2025-53633Shared CWE-405
CVE-2026-24322Same vendor: Sap
CVE-2026-23689Same vendor: Sap
CVE-2025-0066Same vendor: Sap
CVE-2026-23687Same vendor: Sap
CVE-2026-0488Same vendor: Sap

References