VDB
CVE-2026-40131
CVE-2026-40131
PUBLISHED
CVSS 3.4000000953674316 LOW
SQL injection vulnerability exists in @sap/hdi-deploy package, where SQL queries are dynamically constructed using user input without proper parameterization or prepared statements. Successful exploitation could allow the high privileged users to alter the SELECT statements impacting confidentiality and availability of the application. There is no impact on integrity.
EPSS 0.01% · 0.7th percentile
Risk Scores
CVSS 3.1
3.4000000953674316
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:L
EPSS Score
0.01%
0.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| SAP_SE | SAP HANA Deployment Infrastructure (HDI) deploy library | XS_HDI_DEPLOYER 1.00 |
Timeline
- May 12, 2026 CVE Published
- May 12, 2026 PoC Published
- May 12, 2026 Security Advisory
- May 12, 2026 CVE Updated
- May 18, 2026 EPSS Score
- May 19, 2026 EPSS Score
- May 20, 2026 EPSS Score
- May 21, 2026 EPSS Score
- May 22, 2026 EPSS Score
- May 23, 2026 EPSS Score
- May 24, 2026 EPSS Score
- May 25, 2026 EPSS Score