CVE-2026-34264 PUBLISHED

Information Disclosure vulnerability in SAP Human Capital Management for SAP S/4HANA

Assigner: sap
Reserved: 26.03.2026 Published: 14.04.2026 Updated: 14.04.2026

During authorization checks in SAP Human Capital Management for SAP S/4HANA, the system returns specific messages. Due to this, an authenticated user with low privileges could guess and enumerate the content shown, beyond their authorized scope. This leads to disclosure of sensitive information causing a high impact on confidentiality, while integrity and availability are unaffected.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS Score: 6.5

Product Status

Vendor SAP_SE
Product SAP Human Capital Management for SAP S/4HANA
Versions Default: unaffected
  • Version S4HCMRXX 100 is affected
  • Version 101 is affected
  • Version 102 is affected
  • Version SAP_HRRXX 600 is affected
  • Version 604 is affected
  • Version 608 is affected

References

Problem Types