CVE-2026-34264

During authorization checks in SAP Human Capital Management for SAP S/4HANA, the system returns specific messages. Due to this, an authenticated user with low privileges could guess and enumerate the content shown, beyond their authorized scope. This leads to disclosure of sensitive information causing a high impact on confidentiality, while integrity and availability are unaffected.
References
Link Resource
https://me.sap.com/notes/3680767 Permissions Required
https://url.sap/sapsecuritypatchday Permissions Required
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:sap:human_capital_management:s4hcmrxx_100:*:*:*:*:*:*:*
cpe:2.3:a:sap:human_capital_management:s4hcmrxx_101:*:*:*:*:*:*:*
cpe:2.3:a:sap:human_capital_management:s4hcmrxx_102:*:*:*:*:*:*:*
cpe:2.3:a:sap:human_capital_management:sap_hrrxx_600:*:*:*:*:*:*:*
cpe:2.3:a:sap:human_capital_management:sap_hrrxx_604:*:*:*:*:*:*:*
cpe:2.3:a:sap:human_capital_management:sap_hrrxx_608:*:*:*:*:*:*:*
cpe:2.3:a:sap:s\/4hana:-:*:*:*:*:*:*:*

History

04 May 2026, 14:51

Type Values Removed Values Added
References () https://me.sap.com/notes/3680767 - () https://me.sap.com/notes/3680767 - Permissions Required
References () https://url.sap/sapsecuritypatchday - () https://url.sap/sapsecuritypatchday - Permissions Required
CPE cpe:2.3:a:sap:human_capital_management:s4hcmrxx_101:*:*:*:*:*:*:*
cpe:2.3:a:sap:s\/4hana:-:*:*:*:*:*:*:*
cpe:2.3:a:sap:human_capital_management:s4hcmrxx_102:*:*:*:*:*:*:*
cpe:2.3:a:sap:human_capital_management:sap_hrrxx_600:*:*:*:*:*:*:*
cpe:2.3:a:sap:human_capital_management:sap_hrrxx_604:*:*:*:*:*:*:*
cpe:2.3:a:sap:human_capital_management:s4hcmrxx_100:*:*:*:*:*:*:*
cpe:2.3:a:sap:human_capital_management:sap_hrrxx_608:*:*:*:*:*:*:*
First Time Sap human Capital Management
Sap s\/4hana
Sap

14 Apr 2026, 01:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-14 01:16

Updated : 2026-05-04 14:51


NVD link : CVE-2026-34264

Mitre link : CVE-2026-34264

CVE.ORG link : CVE-2026-34264


JSON object : View

Products Affected

sap

  • human_capital_management
  • s\/4hana
CWE
CWE-204

Observable Response Discrepancy