CVE-2026-34256Disclosure

LOWCVSS 7.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Due to a missing authorization check in SAP ERP and SAP S/4HANA (Private Cloud and On-Premise), an authenticated attacker could execute a particular ABAP report to overwrite any existing eight?character executable ABAP report without authorization. If the overwritten report is subsequently executed, the intended functionality could become unavailable. Successful exploitation impacts availability, with a limited impact on integrity confined to the affected report, while confidentiality remains unaffected.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 4 mentions (2026-04-14); latest day: 1
  • 5 total mentions across 2 days

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-04-14: 4Mentions · 2026-04-17: 1Patch / Workaround · 2026-04-14: 1Technical Details · 2026-04-14: 204-1404-17
Signal classification3 categories
Disclosure
360.0%
Patch
120.0%
General
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-144
Disclosure3Patch1
2026-04-171
General1
Full discourse5 posts
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos SAP ❗ CVE-2026-34256 ❗ CVE-2026-27681 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-sap-7/ https://t.co/NZyGfTNrVP

    Post summary

    The tweet merely lists two SAP CVEs and links to a source for more info, offering no technical details, PoC, exploit, or mitigation information.

    00010113
    6.7K followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Patch

    SAP released 20 security notes in April 2026, including critical CVE-2026-27681 SQL injection in Business Planning & Consolidation and BW, plus high-severity CVE-2026-34256 in ERP & S/4 HANA. #SAPSecurity #ABAPPatch #Germany https://ift.tt/wD98s7E

    Post summary

    The tweet announces that SAP has issued security notes for two high‑severity CVEs, providing basic technical details and indicating that patches or advisories are available.

    00010255
    4.0K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-34256 📊 Severity: 7.1 🚨 Risk Level: High 🧩 Affects: Sap Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-34256 #CVE-2026-34256 #CVE #High #Sap #CyberSecurity #InfoSec https://t.co/obdbu68DlV

    Post summary

    The tweet announces a new SAP vulnerability (CVE-2026-34256) with severity 7.1, providing only a reference link.

    0000039
    137 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-34256 Unauthorized ABAP Report Overwrite in SAP ERP and SAP S/4HANA https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-34256

    Post summary

    The text identifies CVE-2026-34256 as an unauthorized ABAP report overwrite in SAP systems but does not provide details on exploitation, patching, or technical specifics.

    0000055
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-34256 Due to a missing authorization check in SAP ERP and SAP S/4HANA (Private Cloud and On-Premise), an authenticated attacker could execute a particular ABAP report to ov… https://www.cve.org/CVERecord?id=CVE-2026-34256

    Post summary

    The passage describes CVE-2026-34256, highlighting a missing auth check in SAP systems that permits authenticated attackers to run an ABAP report, with no PoC, exploit, patch, or active exploitation details provided.

    0000095
    57.2K followersView on X

Explore more