CVE-2026-34260 - Vulnerability Analysis
CriticalCVSS: 9.6Last Updated: May 12, 2026
SAP S/4HANA - SQL Injection
Overview
SAP S/4HANA (SAP Enterprise Search for ABAP) contains a SQL injection caused by direct concatenation of user input into SQL queries, letting authenticated attackers access sensitive data and cause application crashes.
Severity & Score
Impact
Authenticated attackers can access sensitive database information and cause application crashes, impacting confidentiality and availability.
Mitigation
Update to the latest version of SAP S/4HANA (SAP Enterprise Search for ABAP).
Social Media Activity(6 posts)
š“ CVE-2026-34260 - Critical (9.6) SAP S/4HANA (SAP Enterprise Search for ABAP) contains a SQL injection vulnerability that allows an authenticated attacker to inject malicious SQL statements through user-controlled input. The application directly concatenates this malicious user i... š https://www.thehackerwire.com/vulnerability/CVE-2026-34260/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
View original postSAP Security Patch Day May 2026: Critical RCE and SQL Injection Flaws SAP's May 2026 security update addresses 15 vulnerabilities, including two critical flaws (CVE-2026-34263 and CVE-2026-34260) that allow unauthenticated remote code execution and SQL injection. **If you are using SAP products, review the advisory in detail. Prioritize patching the critical missing authentication check in SAP Commerce Cloud and the critical SQL injection vulnerability in SAP S/4HANA Enterprise Search for ABAP, followed by the high-severity OS command injection in SAP Forecasting & Replenishment. Then review the rest of the issues.** #cybersecurity #infosec #advisory #vulnerability https://beyondmachines.net/event_details/sap-security-patch-day-may-2026-critical-rce-and-sql-injection-flaws-w-6-7-x-n/gD2P6Ple2L
View original postšØ CRITICAL: SQL injection (CVE-2026-34260, CVSS 9.6) in SAP S/4HANA (SAP_BASIS 751-816). Authenticated attackers can access sensitive data & crash apps. No patch yet ā restrict access & monitor logs. https://radar.offseq.com/threat/cve-2026-34260-cwe-89-improper-neutralization-of-s-4864cd58 #OffSeq #SAP #Infosec #SQLInjection
View original postš“ CVE-2026-34260 - Critical (9.6) SAP S/4HANA (SAP Enterprise Search for ABAP) contains a SQL injection vulnerability that allows an authenticated attacker to inject malicious SQL statements through user-controlled input. The application directly concatenates this malicious user i... š https://www.thehackerwire.com/vulnerability/CVE-2026-34260/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
View original postSAP Security Patch Day May 2026: Critical RCE and SQL Injection Flaws SAP's May 2026 security update addresses 15 vulnerabilities, including two critical flaws (CVE-2026-34263 and CVE-2026-34260) that allow unauthenticated remote code execution and SQL injection. **If you are using SAP products, review the advisory in detail. Prioritize patching the critical missing authentication check in SAP Commerce Cloud and the critical SQL injection vulnerability in SAP S/4HANA Enterprise Search for ABAP, followed by the high-severity OS command injection in SAP Forecasting & Replenishment. Then review the rest of the issues.** #cybersecurity #infosec #advisory #vulnerability https://beyondmachines.net/event_details/sap-security-patch-day-may-2026-critical-rce-and-sql-injection-flaws-w-6-7-x-n/gD2P6Ple2L
View original postšØ CRITICAL: SQL injection (CVE-2026-34260, CVSS 9.6) in SAP S/4HANA (SAP_BASIS 751-816). Authenticated attackers can access sensitive data & crash apps. No patch yet ā restrict access & monitor logs. https://radar.offseq.com/threat/cve-2026-34260-cwe-89-improper-neutralization-of-s-4864cd58 #OffSeq #SAP #Infosec #SQLInjection
View original postRelated Resources
Details
- CVE ID
- CVE-2026-34260
- Severity
- Critical
- CVSS Score
- 9.6
- Type
- sql_injection
- Status
- unconfirmed
- EPSS
- 1.3%
- Social Posts
- 6
CWE
- CWE-89
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:H