SQL injection vulnerability in SAP S/4HANA (SAP Enterprise Search for ABAP)
Summary
| CVE | CVE-2026-34260 |
|---|---|
| State | PUBLISHED |
| Assigner | sap |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-05-12 03:16:11 UTC |
| Updated | 2026-05-12 03:16:11 UTC |
| Description | SAP S/4HANA (SAP Enterprise Search for ABAP) contains a SQL injection vulnerability that allows an authenticated attacker to inject malicious SQL statements through user-controlled input. The application directly concatenates this malicious user input into SQL queries, which are then passed to the underlying database without proper validation or sanitization. Upon successful exploitation, an attacker may gain unauthorized access to sensitive database information and could potentially crash the application. This vulnerability has a high impact on the confidentiality and availability of the application, while integrity remains unaffected. |
Risk And Classification
Primary CVSS: v3.1 9.6 CRITICAL from [email protected]
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:H
Problem Types: CWE-89 | CWE-89 CWE-89: Improper Neutralization of Special Elements used in an SQL Command
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 9.6 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:H |
| 3.1 | CNA | CVSS | 9.6 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:H |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
ChangedConfidentiality
HighIntegrity
NoneAvailability
HighCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:H
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | SAP SE | SAP S/4HANA SAP Enterprise Search For ABAP | affected SAP_BASIS 751 | Not specified |
| CNA | SAP SE | SAP S/4HANA SAP Enterprise Search For ABAP | affected SAP_BASIS 752 | Not specified |
| CNA | SAP SE | SAP S/4HANA SAP Enterprise Search For ABAP | affected SAP_BASIS 753 | Not specified |
| CNA | SAP SE | SAP S/4HANA SAP Enterprise Search For ABAP | affected SAP_BASIS 754 | Not specified |
| CNA | SAP SE | SAP S/4HANA SAP Enterprise Search For ABAP | affected SAP_BASIS 755 | Not specified |
| CNA | SAP SE | SAP S/4HANA SAP Enterprise Search For ABAP | affected SAP_BASIS 756 | Not specified |
| CNA | SAP SE | SAP S/4HANA SAP Enterprise Search For ABAP | affected SAP_BASIS 757 | Not specified |
| CNA | SAP SE | SAP S/4HANA SAP Enterprise Search For ABAP | affected SAP_BASIS 758 | Not specified |
| CNA | SAP SE | SAP S/4HANA SAP Enterprise Search For ABAP | affected SAP_BASIS 816 | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| me.sap.com/notes/3724838 | [email protected] | me.sap.com | |
| url.sap/sapsecuritypatchday | [email protected] | url.sap | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.