CVE-2026-44753: SAP SE SAP Hana Extended Application Services Classic Model User Self Service

Low severity, CVSS 3.7. EPSS: 0.3% chance of exploitation in the next 30 days.

SAP HANA Database (user self service tools) allows an unauthenticated user to send specially crafted requests that produce distinguishable responses, enabling enumeration of valid user accounts and email addresses. Successful exploitation could allow the attacker to enumerate valid user accounts, resulting in low impact on confidentiality, with no impact on integrity and availability of the application.

Affected products

  • SAP SE SAP Hana Extended Application Services Classic Model User Self Service

Published 2026-07-14. Last modified 2026-07-14.