Artificial Intelligence

SAP AI Core Vulnerabilities Allowed Service Takeover, Customer Data Access

SAP patches AI Core vulnerabilities allowing attackers to access customer data and take over the service.

SAP patches AI Core vulnerabilities allowing attackers to access customer data and take over the service.

SAP’s AI Core service was until recently affected by vulnerabilities that could have allowed attackers to take over the service and access customer data, cloud security giant Wiz reported on Wednesday.

Part of the SAP Business Technology Platform, SAP AI Core enables users to develop, train and run AI services. It can be integrated with SAP and other cloud services for access to the customer’s data. 

Wiz discovered a total of five bugs, which it reported to SAP in January and February. The enterprise software giant released patches for all of the flaws on May 15. 

The security holes, dubbed SAPwned by Wiz, enabled the firm’s researchers to execute arbitrary code, move laterally, and take control of the service, which gave them access to customer data, including credentials for their AWS, Azure and SAP cloud environments. 

“The vulnerabilities we found could have allowed attackers to access customers’ data and contaminate internal artifacts – spreading to related services and other customers’ environments,” Wiz explained.

The company’s researchers managed to read and modify Docker images on SAP’s internal container registry and on Google’s container registry, read and modify artifacts on SAP’s Artifactory server, and gain cluster admin privileges on the AI Core Kubernetes cluster.

Advertisement. Scroll to continue reading.

“The root cause of these issues was the ability for attackers to run malicious AI models and training procedures, which are essentially code,” the security firm said.  

It’s worth noting that conducting such an attack required basic permissions on SAP’s platform. 

Related: Google in Advanced Talks to Buy Wiz for $23B: WSJ Report

Related: Wiz Raises $1 Billion at $12 Billion Valuation

Related: Vulnerability Allowed Takeover of AWS Apache Airflow Service

Related Content

Artificial Intelligence

French President Emmanuel Macron urged the world’s wealthy democracies to work together on regulating advanced AI systems.

Vulnerabilities

CISA has given federal agencies only three days to patch CVE-2026-20253, which can be exploited for unauthenticated remote code execution.

Vulnerabilities

Splunk patched an OS command injection in AI Toolkit, while Atlassian fixed dozens of flaws in third-party dependencies.

Network Security

Insufficient validation of user input allows an attacker to gain access to the underlying OS and elevate their privileges to root.

Vulnerabilities

Critical flaws in NGINX could allow remote, unauthenticated attackers to cause a restart and potentially execute arbitrary code.

ICS/OT

The industrial automation giant has fixed security holes in Logix, CompactLogix, Flex, RSLinx, and FactoryTalk products.

Vulnerabilities

Oracle has released its June 2026 Critical Security Patch Update to fix vulnerabilities in Communications, EBS, Enterprise Manager and other products.

Vulnerabilities

The browser updates address multiple memory safety bugs that could potentially lead to remote code execution.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version