CVE Database
/

CVE-2026-34260

Back to search

CVE-2026-34260

Published: May 12, 2026

Modified: May 12, 2026

PUBLISHED

CVSS v3.1

9.6

CRITICAL

Description

SAP S/4HANA (SAP Enterprise Search for ABAP) contains a SQL injection vulnerability that allows an authenticated attacker to inject malicious SQL statements through user-controlled input. The application directly concatenates this malicious user input into SQL queries, which are then passed to the underlying database without proper validation or sanitization. Upon successful exploitation, an attacker may gain unauthorized access to sensitive database information and could potentially crash the application. This vulnerability has a high impact on the confidentiality and availability of the application, while integrity remains unaffected.

VendorProductVersions

SAP_SE

SAP S/4HANA (SAP Enterprise Search for ABAP)

affected
SAP_BASIS 751
affected
SAP_BASIS 752
affected
SAP_BASIS 753
affected
SAP_BASIS 754
affected
SAP_BASIS 755

+4 more versions

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:H

Attack Vector

Network

Attack Complexity

Low

Privileges Required

Low

User Interaction

None

Scope

Changed

Confidentiality

High

Integrity

None

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now