CVE-2026-34256

7.1

SAP · ERP and S/4HANA

A missing authorization check in SAP ERP and S/4HANA allows an authenticated attacker to overwrite existing eight-character ABAP reports, potentially causing service disruption.

Executive summary

An authenticated attacker can exploit a missing authorization check in SAP ERP and S/4HANA to overwrite critical ABAP reports, leading to significant system availability risks.

Vulnerability

The vulnerability is a missing authorization check (CWE-862) that allows an authenticated user to overwrite specific ABAP reports. The attack requires the user to have valid system access, though no elevated administrative privileges are stated as a requirement for the trigger.

Business impact

Successful exploitation compromises system availability by allowing an attacker to corrupt or replace executable reports. While confidentiality is not impacted, the ability to overwrite reports can lead to unauthorized changes to core business processes or denial of service for critical functions. With a CVSS score of 7.1, this is a High severity issue that requires immediate attention to prevent operational disruption.

Remediation

Immediate Action: Review the SAP security note 3731908 and apply the corresponding security updates or configuration changes provided by SAP to address the authorization gap.

Proactive Monitoring: Monitor system logs for unauthorized attempts to modify or overwrite existing ABAP reports, focusing on user activity involving report execution and modification.

Compensating Controls: Implement strict Role-Based Access Control (RBAC) to limit the number of users who possess the necessary permissions to execute or modify ABAP report objects.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the potential for service disruption and the High severity rating, organizations should prioritize the identification of affected SAP instances within their environment. Applying the vendor-provided patches or configuration changes is essential to ensure the integrity of your ABAP environment and to prevent unauthorized report modifications.

More SAP CVEs

Sources