CVE-2026-34264 Details
Description
During authorization checks in SAP Human Capital Management for SAP S/4HANA, the system returns specific messages. Due to this, an authenticated user with low privileges could guess and enumerate the content shown, beyond their authorized scope. This leads to disclosure of sensitive information causing a high impact on confidentiality, while integrity and availability are unaffected.
A vulnerability exists in SAP Human Capital Management for SAP S/4HANA during authorization checks, where the system inadvertently reveals specific messages. This flaw enables an authenticated user with low privileges to guess and enumerate information beyond their authorized access, leading to the disclosure of sensitive data and causing a significant breach of confidentiality. However, integrity and availability remain unaffected.
Users are advised to consult the SAP Security Notes for guidance on addressing this vulnerability. SAP Security Notes can be accessed through the SAP for Me platform, specifically in the 'Security Notes' section. It is recommended to implement these security corrections as a priority.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 14, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://me.sap.com/notes/3680767 | [email protected] | Permissions Required |
| https://url.sap/sapsecuritypatchday | [email protected] | Permissions Required |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-204 | Observable Response Discrepancy | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| sap human capital management | s4hcmrxx_100 s4hcmrxx_101 s4hcmrxx_102 sap_hrrxx_600 sap_hrrxx_604 sap_hrrxx_608 |
CPE
Remediation
| |
| sap s/4hana | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 4, 2026 | Initial Analysis | [email protected] |
| Apr 14, 2026 | New CVE Received | [email protected] |