LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-34260

CVE-2026-34260 - Vulnerability Analysis

CriticalCVSS: 9.6

Last Updated: May 12, 2026

SAP S/4HANA - SQL Injection

Published: May 12, 2026Updated: May 12, 2026Remote Exploitable

Overview

SAP S/4HANA (SAP Enterprise Search for ABAP) contains a SQL injection caused by direct concatenation of user input into SQL queries, letting authenticated attackers access sensitive data and cause application crashes.

Severity & Score

Severity: Critical
CVSS Score: 9.6
EPSS Score: 1.3%(Probability of exploitation in next 30 days)

Impact

Authenticated attackers can access sensitive database information and cause application crashes, impacting confidentiality and availability.

Mitigation

Update to the latest version of SAP S/4HANA (SAP Enterprise Search for ABAP).

Social Media Activity(6 posts)

TheHackerWire
TheHackerWire
@thehackerwire
May 12, 2026

šŸ”“ CVE-2026-34260 - Critical (9.6) SAP S/4HANA (SAP Enterprise Search for ABAP) contains a SQL injection vulnerability that allows an authenticated attacker to inject malicious SQL statements through user-controlled input. The application directly concatenates this malicious user i... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-34260/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post
BeyondMachines :verified:
BeyondMachines :verified:
@beyondmachines1
May 12, 2026

SAP Security Patch Day May 2026: Critical RCE and SQL Injection Flaws SAP's May 2026 security update addresses 15 vulnerabilities, including two critical flaws (CVE-2026-34263 and CVE-2026-34260) that allow unauthenticated remote code execution and SQL injection. **If you are using SAP products, review the advisory in detail. Prioritize patching the critical missing authentication check in SAP Commerce Cloud and the critical SQL injection vulnerability in SAP S/4HANA Enterprise Search for ABAP, followed by the high-severity OS command injection in SAP Forecasting & Replenishment. Then review the rest of the issues.** #cybersecurity #infosec #advisory #vulnerability https://beyondmachines.net/event_details/sap-security-patch-day-may-2026-critical-rce-and-sql-injection-flaws-w-6-7-x-n/gD2P6Ple2L

View original post
OffSequence
OffSequence
@offseq
May 12, 2026

🚨 CRITICAL: SQL injection (CVE-2026-34260, CVSS 9.6) in SAP S/4HANA (SAP_BASIS 751-816). Authenticated attackers can access sensitive data & crash apps. No patch yet — restrict access & monitor logs. https://radar.offseq.com/threat/cve-2026-34260-cwe-89-improper-neutralization-of-s-4864cd58 #OffSeq #SAP #Infosec #SQLInjection

View original post
TheHackerWire
TheHackerWire
@thehackerwire
May 12, 2026

šŸ”“ CVE-2026-34260 - Critical (9.6) SAP S/4HANA (SAP Enterprise Search for ABAP) contains a SQL injection vulnerability that allows an authenticated attacker to inject malicious SQL statements through user-controlled input. The application directly concatenates this malicious user i... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-34260/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post
BeyondMachines :verified:
BeyondMachines :verified:
@beyondmachines1
May 12, 2026

SAP Security Patch Day May 2026: Critical RCE and SQL Injection Flaws SAP's May 2026 security update addresses 15 vulnerabilities, including two critical flaws (CVE-2026-34263 and CVE-2026-34260) that allow unauthenticated remote code execution and SQL injection. **If you are using SAP products, review the advisory in detail. Prioritize patching the critical missing authentication check in SAP Commerce Cloud and the critical SQL injection vulnerability in SAP S/4HANA Enterprise Search for ABAP, followed by the high-severity OS command injection in SAP Forecasting & Replenishment. Then review the rest of the issues.** #cybersecurity #infosec #advisory #vulnerability https://beyondmachines.net/event_details/sap-security-patch-day-may-2026-critical-rce-and-sql-injection-flaws-w-6-7-x-n/gD2P6Ple2L

View original post
OffSequence
OffSequence
@offseq
May 12, 2026

🚨 CRITICAL: SQL injection (CVE-2026-34260, CVSS 9.6) in SAP S/4HANA (SAP_BASIS 751-816). Authenticated attackers can access sensitive data & crash apps. No patch yet — restrict access & monitor logs. https://radar.offseq.com/threat/cve-2026-34260-cwe-89-improper-neutralization-of-s-4864cd58 #OffSeq #SAP #Infosec #SQLInjection

View original post

Details

CVE ID
CVE-2026-34260
Severity
Critical
CVSS Score
9.6
Type
sql_injection
Status
unconfirmed
EPSS
1.3%
Social Posts
6

CWE

  • CWE-89

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:H

EPSS Score

1.3%Probability of exploitation in the next 30 days