CVE-2026-34264
This leads to disclosure of sensitive information causing a high impact on confidentiality, while integrity and availability are unaffected.
Does this matter?
Lower severity and a low EPSS score (0.27%). Track it; it rarely justifies an emergency change on its own.
Description
During authorization checks in SAP Human Capital Management for SAP S/4HANA, the system returns specific messages. Due to this, an authenticated user with low privileges could guess and enumerate the content shown, beyond their authorized scope. This leads to disclosure of sensitive information causing a high impact on confidentiality, while integrity and availability are unaffected.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.27% probability · 19th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-204
- Affected
- sap/human capital management
- Source
- cna@sap.com
References
- https://me.sap.com/notes/3680767Permissions Required
- https://url.sap/sapsecuritypatchdayPermissions Required
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.