CVE-2026-0501: SAP SE SAP s/4hana Private Cloud And On-Premise Financials � General Ledger

Critical severity, CVSS 9.9. EPSS: 0.5% chance of exploitation in the next 30 days.

Due to insufficient input validation in SAP S/4HANA Private Cloud and On-Premise (Financials General Ledger), an authenticated user could execute crafted SQL queries to read, modify, and delete backend database data. This leads to a high impact on the confidentiality, integrity, and availability of the application.

Affected products

  • SAP SE SAP s/4hana Private Cloud And On-Premise Financials � General Ledger: version S4CORE 102 only; version 103 only; version 104 only; version 105 only; version 106 only; version 107 only; …

Published 2026-01-13. Last modified 2026-06-17.