Vulnerability intelligence
CVE-2026-34260
SAP S/4HANA (SAP Enterprise Search for ABAP) contains a SQL injection vulnerability that allows an authenticated attacker to inject malicious SQL statements through user-controlled input. The application directly concatenates this malicious user input into SQL queries, which are then passed to the underlying database without proper validation or sanitization. Upon successful exploitation, an attacker may gain unauthorized access to sensitive database information and could potentially crash the application. This vulnerability has a high impact on the confidentiality and availability of the application, while integrity remains unaffected.
CVSS Score
9.6
Critical
EPSS — Exploit Probability
0.5%
Riskier than 37% of all CVEs
Exploitation
Not in CISA KEV
No federal exploitation record
Remediation
unknown
Check vendor advisories
2 articles across 2 outlets · first covered May 12, 2026 · latest May 18, 2026
Coverage timeline
-
Ivanti, Fortinet, SAP, VMware, n8n Patch RCE, SQL Injection, Privilege Escalation Flawsthehackernews.com · May 18, 2026
-
SAP Patches Critical S/4HANA, Commerce Vulnerabilitieswww.securityweek.com · May 12, 2026