← Back

CVE-2026-34264

nvd nist
Published: Apr 14, 2026Modified: Jun 17, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: CNA (Secondary)

Description

During authorization checks in SAP Human Capital Management for SAP S/4HANA, the system returns specific messages. Due to this, an authenticated user with low privileges could guess and enumerate the content shown, beyond their authorized scope. This leads to disclosure of sensitive information causing a high impact on confidentiality, while integrity and availability are unaffected.

Affected (6)

1 product
Human Capital Management
Configuration A
6 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Sap
Version s4hcmrxx_100
Version s4hcmrxx_101
Version s4hcmrxx_102
Version sap_hrrxx_600
Version sap_hrrxx_604
Version sap_hrrxx_608
Running on/withPlatform Versions
Sap
S/4hana
All versions

References (2)

Source: cna@sap.com
Permissions Required
Source: cna@sap.com
Permissions Required

Timeline

No history available yet.