SAP HANA database is vulnerable to privilege escalation allowing an attacker with valid credentials of any user to switch to another user potentially gaining administrative access. This exploit could result in a total compromise of the system�s confidentiality, integrity, and availability.
References
| Link | Resource |
|---|---|
| https://me.sap.com/notes/3691059 | Permissions Required |
| https://url.sap/sapsecuritypatchday | Patch |
Configurations
History
27 Jan 2026, 20:18
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:sap:hana_database:2.00:*:*:*:*:*:*:* | |
| References | () https://me.sap.com/notes/3691059 - Permissions Required | |
| References | () https://url.sap/sapsecuritypatchday - Patch | |
| First Time |
Sap hana Database
Sap |
13 Jan 2026, 02:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-13 02:15
Updated : 2026-01-27 20:18
NVD link : CVE-2026-0492
Mitre link : CVE-2026-0492
CVE.ORG link : CVE-2026-0492
JSON object : View
Products Affected
sap
- hana_database
CWE
CWE-306
Missing Authentication for Critical Function
