CVE 8.2 HIGH

OS Command Injection Vulnerability in SAP Forecasting & Replenishment_CVE-2026-34259

8.2 / 10
HIGH
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Description

Due to an OS Command Execution vulnerability in SAP Forecasting & Replenishment, an authenticated attacker with administrative authorizations could abuse a non-remote-enabled function to execute arbitrary operating system commands. Successful exploitation could allow the attacker to read or modify any system data or shut down the system, resulting in a complete compromise of confidentiality, integrity, and availability.

Basic Information

ID CVE-2026-34259
Source sap
Published May 12, 2026 at 02:20

Affected Product

Vendor SAP_SE
Product SAP Forecasting & Replenishment
Version SCM 702
Affected Versions SAP_SE SAP Forecasting & Replenishment SCM 702
SAP_SE SAP Forecasting & Replenishment 712
SAP_SE SAP Forecasting & Replenishment 713
SAP_SE SAP Forecasting & Replenishment 714

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.