CVE 7.1 HIGH

Missing Authorization check in SAP ERP and SAP S/4 HANA (Private Cloud and On-Premise)_CVE-2026-34256

7.1 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H

Description

Due to a missing authorization check in SAP ERP and SAP S/4HANA (Private Cloud and On-Premise), an authenticated attacker could execute a particular ABAP report to overwrite any existing eight?character executable ABAP report without authorization. If the overwritten report is subsequently executed, the intended functionality could become unavailable. Successful exploitation impacts availability, with a limited impact on integrity confined to the affected report, while confidentiality remains unaffected.

Basic Information

ID CVE-2026-34256
Source sap
Published Apr 14, 2026 at 00:08

Affected Product

Vendor SAP_SE
Product SAP ERP and SAP S/4 HANA (Private Cloud and On-Premise)
Version SAP_FIN 618
Affected Versions SAP_SE SAP ERP and SAP S/4 HANA (Private Cloud and On-Premise) SAP_FIN 618
SAP_SE SAP ERP and SAP S/4 HANA (Private Cloud and On-Premise) 720
SAP_SE SAP ERP and SAP S/4 HANA (Private Cloud and On-Premise) 730
SAP_SE SAP ERP and SAP S/4 HANA (Private Cloud and On-Premise) EA-FIN 617
SAP_SE SAP ERP and SAP S/4 HANA (Private Cloud and On-Premise) 700
SAP_SE SAP ERP and SAP S/4 HANA (Private Cloud and On-Premise) SAPSCORE 135
SAP_SE SAP ERP and SAP S/4 HANA (Private Cloud and On-Premise) S4CORE 102
SAP_SE SAP ERP and SAP S/4 HANA (Private Cloud and On-Premise) 103
SAP_SE SAP ERP and SAP S/4 HANA (Private Cloud and On-Premise) 104
SAP_SE SAP ERP and SAP S/4 HANA (Private Cloud and On-Premise) 105
SAP_SE SAP ERP and SAP S/4 HANA (Private Cloud and On-Premise) 106
SAP_SE SAP ERP and SAP S/4 HANA (Private Cloud and On-Premise) 107
SAP_SE SAP ERP and SAP S/4 HANA (Private Cloud and On-Premise) 108
SAP_SE SAP ERP and SAP S/4 HANA (Private Cloud and On-Premise) 109
SAP_SE SAP ERP and SAP S/4 HANA (Private Cloud and On-Premise) EA-APPL 600
SAP_SE SAP ERP and SAP S/4 HANA (Private Cloud and On-Premise) 602
SAP_SE SAP ERP and SAP S/4 HANA (Private Cloud and On-Premise) 603
SAP_SE SAP ERP and SAP S/4 HANA (Private Cloud and On-Premise) 604
SAP_SE SAP ERP and SAP S/4 HANA (Private Cloud and On-Premise) 605
SAP_SE SAP ERP and SAP S/4 HANA (Private Cloud and On-Premise) 606

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.