Artificial Intelligence

SAP AI Core Vulnerabilities Allowed Service Takeover, Customer Data Access

SAP patches AI Core vulnerabilities allowing attackers to access customer data and take over the service.

SAP patches AI Core vulnerabilities allowing attackers to access customer data and take over the service.

SAP’s AI Core service was until recently affected by vulnerabilities that could have allowed attackers to take over the service and access customer data, cloud security giant Wiz reported on Wednesday.

Part of the SAP Business Technology Platform, SAP AI Core enables users to develop, train and run AI services. It can be integrated with SAP and other cloud services for access to the customer’s data. 

Wiz discovered a total of five bugs, which it reported to SAP in January and February. The enterprise software giant released patches for all of the flaws on May 15. 

The security holes, dubbed SAPwned by Wiz, enabled the firm’s researchers to execute arbitrary code, move laterally, and take control of the service, which gave them access to customer data, including credentials for their AWS, Azure and SAP cloud environments. 

“The vulnerabilities we found could have allowed attackers to access customers’ data and contaminate internal artifacts – spreading to related services and other customers’ environments,” Wiz explained.

The company’s researchers managed to read and modify Docker images on SAP’s internal container registry and on Google’s container registry, read and modify artifacts on SAP’s Artifactory server, and gain cluster admin privileges on the AI Core Kubernetes cluster.

Advertisement. Scroll to continue reading.

“The root cause of these issues was the ability for attackers to run malicious AI models and training procedures, which are essentially code,” the security firm said.  

It’s worth noting that conducting such an attack required basic permissions on SAP’s platform. 

Related: Google in Advanced Talks to Buy Wiz for $23B: WSJ Report

Related: Wiz Raises $1 Billion at $12 Billion Valuation

Related: Vulnerability Allowed Takeover of AWS Apache Airflow Service

Related Content

Artificial Intelligence

The RovoBlast attack method identified by Varonis researchers could have been exploited to steal Confluence, Jira and SharePoint data.

Endpoint Security

Microsoft fixed critical vulnerabilities across Azure, Entra, and SharePoint, while Apple patched a high-severity authentication bypass.

Vulnerabilities

The browser refresh eliminates over two dozen memory safety bugs, including critical use-after-free flaws.

Artificial Intelligence

Zenity researchers reported the findings to Anthropic and OpenAI in late 2025 and early 2026, but they remain unpatched.

Artificial Intelligence

An attacker could self-register, sign in for board-level API access, and import a new company for code execution.

Artificial Intelligence

The incident involved a testing environment set up by Irregular, similar to what Anthropic reported last week.

Vulnerabilities

Patches were rolled out for two dozen vulnerabilities, including one with public proof-of-concept (PoC) code.

Vulnerabilities

Tracked as CVE-2026-63077, the critical bug can be exploited without authentication for remote code execution.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version