CVE-2026-34260
CVE-2026-34260, CVSS: 9.6 SQL injection vulnerability in SAP S/4HANA (SAP Enterprise Search for ABAP) caused by the improper neutralization of special elements in SQL commands (CWE-89). An authenticated attacker can inject malicious SQL statements through user-controlled input. These commands are executed by the underlying database, allowing for unauthorized access to sensitive records. CVE-2026-34263, CVSS: 9.6 Missing authentication check vulnerability in SAP Commerce Cloud due to an improper Spring Security configuration. This flaw allows an unauthenticated attacker to bypass security filters, potentially enabling unauthorized configuration uploads. While not classified as direct RCE, the bypass provides a significant foothold for further exploitation within the application environment.
EPSS 0.02% · 3.2th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| SAP | SAP S/4HANA (SAP Enterprise Search for ABAP): SAP_BASIS 751, 752, 753, 754, 755, 756, 757, 758, 812, 813, 815, and 816 | |
| SAP | SAP Commerce cloud: HY_COM 2205, COM_CLOUD 2211, 2211-JDK21 |
Timeline
- May 12, 2026 CVE Published
- May 12, 2026 PoC Published
- May 12, 2026 Security Advisory
- May 12, 2026 CVE Updated
- May 18, 2026 EPSS Score
- May 19, 2026 EPSS Score
- May 20, 2026 EPSS Score
- May 21, 2026 EPSS Score
- May 22, 2026 EPSS Score
- May 23, 2026 EPSS Score
- May 24, 2026 EPSS Score
- May 25, 2026 EPSS Score
References
- https://ccb.belgium.be/advisories/warning-critical-sql-injection-missing-authentication-check-sap-cve-2026-34260-cve-2026 advisory
- https://support.sap.com/en/my-support/knowledge-base/security-notes-news/may-2026.html vendor
- https://nvd.nist.gov/vuln/detail/CVE-2026-34260 technical
- https://nvd.nist.gov/vuln/detail/CVE-2026-34263 technical