CVEPublished 2026-04-14Modified 2026-05-040 articles on news6 live referencesNVD data

CVE-2026-34264Sap · Human_capital_management

Vulnerability data via NVD (ingested)

CVSS v3.1
6.5
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS percentile
10
Exploit Prediction Scoring System · top 90% of all CVEs
Description

During authorization checks in SAP Human Capital Management for SAP S/4HANA, the system returns specific messages. Due to this, an authenticated user with low privileges could guess and enumerate the content shown, beyond their authorized scope. This leads to disclosure of sensitive information causing a high impact on confidentiality, while integrity and availability are unaffected.

Timeline
Published 2026-04-14
Modified 2026-05-04

External references

Search for exposed instances

Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).

More intel sources (5)

Known PoCs on GitHub

No public proof-of-concept repositories found for CVE-2026-34264 on GitHub.
We haven't classified any articles referencing CVE-2026-34264 yet. The external references above still apply.