SAP ERP/S4HANA ABAP Report Overwrite via Missing Auth Check
CVE-2026-34256 Published on April 14, 2026
Missing Authorization check in SAP ERP and SAP S/4 HANA (Private Cloud and On-Premise)
Due to a missing authorization check in SAP ERP and SAP S/4HANA (Private Cloud and On-Premise), an authenticated attacker could execute a particular ABAP report to overwrite any existing eight?character executable ABAP report without authorization. If the overwritten report is subsequently executed, the intended functionality could become unavailable. Successful exploitation impacts availability, with a limited impact on integrity confined to the affected report, while confidentiality remains unaffected.
Vulnerability Analysis
CVE-2026-34256 is exploitable with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality, with no impact on integrity, and a high impact on availability.
Weakness Type
What is an AuthZ Vulnerability?
The software does not perform an authorization check when an actor attempts to access a resource or perform an action.
CVE-2026-34256 has been classified to as an AuthZ vulnerability or weakness.
Products Associated with CVE-2026-34256
Want to know whenever a new CVE is published for SAP S4hana? stack.watch will email you.
Affected Versions
SAP_SE SAP ERP and SAP S/4 HANA (Private Cloud and On-Premise):- Version SAP_FIN 618 is affected.
- Version 720 is affected.
- Version 730 is affected.
- Version EA-FIN 617 is affected.
- Version 700 is affected.
- Version SAPSCORE 135 is affected.
- Version S4CORE 102 is affected.
- Version 103 is affected.
- Version 104 is affected.
- Version 105 is affected.
- Version 106 is affected.
- Version 107 is affected.
- Version 108 is affected.
- Version 109 is affected.
- Version EA-APPL 600 is affected.
- Version 602 is affected.
- Version 603 is affected.
- Version 604 is affected.
- Version 605 is affected.
- Version 606 is affected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.