VDB

CVE-2026-34260

CVE-2026-34260 PUBLISHED CVSS 9.600000381469727 CRITICAL

CVE-2026-34260, CVSS: 9.6 SQL injection vulnerability in SAP S/4HANA (SAP Enterprise Search for ABAP) caused by the improper neutralization of special elements in SQL commands (CWE-89). An authenticated attacker can inject malicious SQL statements through user-controlled input. These commands are executed by the underlying database, allowing for unauthorized access to sensitive records. CVE-2026-34263, CVSS: 9.6 Missing authentication check vulnerability in SAP Commerce Cloud due to an improper Spring Security configuration. This flaw allows an unauthenticated attacker to bypass security filters, potentially enabling unauthorized configuration uploads. While not classified as direct RCE, the bypass provides a significant foothold for further exploitation within the application environment.

EPSS 0.02% · 3.2th percentile

Risk Scores

CVSS 3.1
9.600000381469727
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
EPSS Score
0.02%
3.2th percentile

Affected Products

VendorProductVersions
SAPSAP S/4HANA (SAP Enterprise Search for ABAP): SAP_BASIS 751, 752, 753, 754, 755, 756, 757, 758, 812, 813, 815, and 816
SAPSAP Commerce cloud: HY_COM 2205, COM_CLOUD 2211, 2211-JDK21

Timeline

  • May 12, 2026 CVE Published
  • May 12, 2026 PoC Published
  • May 12, 2026 Security Advisory
  • May 12, 2026 CVE Updated
  • May 18, 2026 EPSS Score
  • May 19, 2026 EPSS Score
  • May 20, 2026 EPSS Score
  • May 21, 2026 EPSS Score
  • May 22, 2026 EPSS Score
  • May 23, 2026 EPSS Score
  • May 24, 2026 EPSS Score
  • May 25, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›