CVE-2026-34261 PUBLISHED

Missing Authorization check in SAP Business Analytics and SAP Content Management

Assigner: sap
Reserved: 26.03.2026 Published: 14.04.2026 Updated: 14.04.2026

Due to a missing authorization check in SAP Business Analytics and SAP Content Management, an authenticated user could make unauthorized calls to certain remote function modules, potentially accessing sensitive information beyond their intended permissions. This vulnerability affects confidentiality, with no impact on integrity and availability.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS Score: 6.5

Product Status

Vendor SAP_SE
Product SAP Business Analytics and SAP Content Management
Versions Default: unaffected
  • Version S4HCMRXX 100 is affected
  • Version 101 is affected
  • Version 102 is affected
  • Version SAP_HRRXX 600 is affected
  • Version 604 is affected
  • Version 608 is affected

References

Problem Types