CVE-2026-34261: SAP SE SAP Business Analytics And SAP Content Management

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

Due to a missing authorization check in SAP Business Analytics and SAP Content Management, an authenticated user could make unauthorized calls to certain remote function modules, potentially accessing sensitive information beyond their intended permissions. This vulnerability affects confidentiality, with no impact on integrity and availability.

Affected products

  • SAP SE SAP Business Analytics And SAP Content Management: version S4HCMRXX 100 only; version 101 only; version 102 only; version 604 only; version 608 only

Published 2026-04-14. Last modified 2026-06-17.