CVE-2026-34264: SAP Human Capital Management
Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.
During authorization checks in SAP Human Capital Management for SAP S/4HANA, the system returns specific messages. Due to this, an authenticated user with low privileges could guess and enumerate the content shown, beyond their authorized scope. This leads to disclosure of sensitive information causing a high impact on confidentiality, while integrity and availability are unaffected.
Affected products
- SAP Human Capital Management: version s4hcmrxx_100 only; version s4hcmrxx_101 only; version s4hcmrxx_102 only; version sap_hrrxx_600 only; version sap_hrrxx_604 only; version sap_hrrxx_608 only
Published 2026-04-14. Last modified 2026-06-17.