VDB

CVE-2026-40131

CVE-2026-40131 PUBLISHED CVSS 3.4000000953674316 LOW

SQL injection vulnerability exists in @sap/hdi-deploy package, where SQL queries are dynamically constructed using user input without proper parameterization or prepared statements. Successful exploitation could allow the high privileged users to alter the SELECT statements impacting confidentiality and availability of the application. There is no impact on integrity.

EPSS 0.01% · 0.7th percentile

Risk Scores

CVSS 3.1
3.4000000953674316
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:L
EPSS Score
0.01%
0.7th percentile

Affected Products

VendorProductVersions
SAP_SESAP HANA Deployment Infrastructure (HDI) deploy libraryXS_HDI_DEPLOYER 1.00

Timeline

  • May 12, 2026 CVE Published
  • May 12, 2026 PoC Published
  • May 12, 2026 Security Advisory
  • May 12, 2026 CVE Updated
  • May 18, 2026 EPSS Score
  • May 19, 2026 EPSS Score
  • May 20, 2026 EPSS Score
  • May 21, 2026 EPSS Score
  • May 22, 2026 EPSS Score
  • May 23, 2026 EPSS Score
  • May 24, 2026 EPSS Score
  • May 25, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›